Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2018-12256 admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code e… Litecart 2.1.3+ Fix from $1,9502018-08-16 HIGH 8.8 CVE-2018-15139EPSS 19% Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to exe… Openemr 5.0.1.4+ Fix from $1,9502018-08-13 HIGH 7.2 CVE-2018-14028EPSS 15% In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP fil… WordPress Patch available Fix from $1,9502018-08-10 CRITICAL 9.8 CVE-2018-15137EPSS 18% CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code ex… Clr M20 Firmware No fix yet Fix from $2,3002018-08-08 HIGH 8.8 CVE-2018-14857 Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server thr… Ocs Inventory Server after 2.5 Fix from $1,9502018-08-06 HIGH 7.2 CVE-2018-14911 A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filtering the file upload type. A… Ukcms after 1.1.7 Fix from $1,9502018-08-03 HIGH 7.2 CVE-2018-12468 A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an admini… Groupwise 18.0.2+ Fix from $1,9502018-08-01 HIGH 8.8 CVE-2018-12940 Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to ex… Seeddms 5.1.8+ Fix from $1,9502018-07-31 HIGH 8.1 CVE-2017-3189EPSS 7% The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When… Dotcms after 3.7.1 Fix from $1,9502018-07-24 HIGH 8.8 CVE-2018-14570 A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to… B2b2c Multi Business No fix yet Fix from $1,9502018-07-23 CRITICAL 9.8 CVE-2018-14441 An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upl… Ssh Companywebsite after 2018-05-03 Fix from $2,3002018-07-20 CRITICAL 9.8 CVE-2018-14334 manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm va… Joyplus Cms No fix yet Fix from $2,3002018-07-17 CRITICAL 9.8 CVE-2018-13981EPSS 17% The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default co… Zeta Producer Desktop Cms 14.2.1+ Fix from $2,3002018-07-16 CRITICAL 9.8 CVE-2016-9492 The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated… Php Formmail Generator 2016-12-17+ Fix from $2,3002018-07-13 HIGH 8.8 CVE-2018-12980EPSS 30% An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated use… 762 3000 Firmware 02+ Fix from $1,9502018-07-12 HIGH 8.8 CVE-2018-1000619 Ovidentia version 8.4.3 and earlier contains a Unsanitized User Input vulnerability in utilit.php, bab_getAddonFilePathfromTg that can result in Auth… Ovidentia after 8.4.3 Fix from $1,9502018-07-09 HIGH 7.2 CVE-2018-11638 Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated … Powermedia Xms after 3.5 Fix from $1,9502018-07-03 CRITICAL 9.8 CVE-2018-12426EPSS 5% The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation … Live Chat 8.0.07+ Fix from $2,3002018-07-02 HIGH 8.1 CVE-2018-12528 An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration fil… N150 Firmware No fix yet Fix from $1,9502018-07-02 CRITICAL 9.8 CVE-2018-13038 OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uplo… Opensid No fix yet Fix from $2,3002018-07-01 HIGH 7.2 CVE-2018-13021 An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.ph… Hongcms No fix yet Fix from $1,9502018-06-29 HIGH 7.2 CVE-2018-13024 Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an… Metinfo No fix yet Fix from $1,9502018-06-29 CRITICAL 9.8 CVE-2018-12914 A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct… Publiccms No fix yet Fix from $2,3002018-06-27 CRITICAL 9.8 CVE-2018-1000544 rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary … Debian Linux after 1.2.1 Fix from $2,3002018-06-26 HIGH 8.8 CVE-2018-12519EPSS 8% An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js applicatio… Shopnx No fix yet Fix from $1,9502018-06-19 CRITICAL 9.8 CVE-2018-11221EPSS 6% Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/up… Pandora Fms after 7.23 Fix from $2,3002018-06-16 CRITICAL 9.8 CVE-2018-12491 PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploadin… Phpok No fix yet Fix from $2,3002018-06-15 CRITICAL 9.8 CVE-2011-4183 A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2… Open Build Service 2.1.16+ Fix from $2,3002018-06-13 HIGH 8.8 CVE-2018-12263 portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI. Portfoliocms Mitigation only Fix from $1,9502018-06-13 HIGH 8.8 CVE-2018-1453 IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be autom… Security Identity Manager Patch available Fix from $1,9502018-06-08