Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2018-12256
admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code e…
Litecart
2.1.3+
HIGH 8.8
CVE-2018-15139EPSS 19%
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to exe…
Openemr
5.0.1.4+
HIGH 7.2
CVE-2018-14028EPSS 15%
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP fil…
WordPress
Patch available
CRITICAL 9.8
CVE-2018-15137EPSS 18%
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code ex…
Clr M20 Firmware
No fix yet
HIGH 8.8
CVE-2018-14857
Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server thr…
Ocs Inventory Server
after 2.5
HIGH 7.2
CVE-2018-14911
A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filtering the file upload type. A…
Ukcms
after 1.1.7
HIGH 7.2
CVE-2018-12468
A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an admini…
Groupwise
18.0.2+
HIGH 8.8
CVE-2018-12940
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to ex…
Seeddms
5.1.8+
HIGH 8.1
CVE-2017-3189EPSS 7%
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When…
Dotcms
after 3.7.1
HIGH 8.8
CVE-2018-14570
A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to…
B2b2c Multi Business
No fix yet
CRITICAL 9.8
CVE-2018-14441
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upl…
Ssh Companywebsite
after 2018-05-03
CRITICAL 9.8
CVE-2018-14334
manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm va…
Joyplus Cms
No fix yet
CRITICAL 9.8
CVE-2018-13981EPSS 17%
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default co…
Zeta Producer Desktop Cms
14.2.1+
CRITICAL 9.8
CVE-2016-9492
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated…
Php Formmail Generator
2016-12-17+
HIGH 8.8
CVE-2018-12980EPSS 30%
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated use…
762 3000 Firmware
02+
HIGH 8.8
CVE-2018-1000619
Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathfromTg that can result in Auth…
Ovidentia
after 8.4.3
HIGH 7.2
CVE-2018-11638
Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated …
Powermedia Xms
after 3.5
CRITICAL 9.8
CVE-2018-12426EPSS 5%
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation …
Live Chat
8.0.07+
HIGH 8.1
CVE-2018-12528
An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration fil…
N150 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-13038
OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uplo…
Opensid
No fix yet
HIGH 7.2
CVE-2018-13021
An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.ph…
Hongcms
No fix yet
HIGH 7.2
CVE-2018-13024
Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an…
Metinfo
No fix yet
CRITICAL 9.8
CVE-2018-12914
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct…
Publiccms
No fix yet
CRITICAL 9.8
CVE-2018-1000544
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary …
Debian Linux
after 1.2.1
HIGH 8.8
CVE-2018-12519EPSS 8%
An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js applicatio…
Shopnx
No fix yet
CRITICAL 9.8
CVE-2018-11221EPSS 6%
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/up…
Pandora Fms
after 7.23
CRITICAL 9.8
CVE-2018-12491
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploadin…
Phpok
No fix yet
CRITICAL 9.8
CVE-2011-4183
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2…
Open Build Service
2.1.16+
HIGH 8.8
CVE-2018-12263
portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.
Portfoliocms
Mitigation only
HIGH 8.8
CVE-2018-1453
IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be autom…
Security Identity Manager
Patch available