Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2018-12051 Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as … Schools Alert Management Script No fix yet Fix from $2,3002018-06-08 CRITICAL 9.8 CVE-2018-12045 DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfi… Dedecms 5.7+ Fix from $2,3002018-06-08 HIGH 8.8 CVE-2018-3758EPSS 27% Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine. Express Cart 1.1.7+ Fix from $1,9502018-06-07 HIGH 7.2 CVE-2018-1265 Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF a… Cf Deployment 1.37.0 / 2.8.0+ Fix from $1,9502018-06-06 CRITICAL 9.8 CVE-2018-11736EPSS 9% An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using th… Pluck after 4.7.7 Fix from $2,3002018-06-05 HIGH 7.5 CVE-2018-11196 Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files int… Mahara 17.04.8 / 17.10.5+ Fix from $1,9502018-06-01 HIGH 8.8 CVE-2018-11392 An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the En… Php Login \& User Management 4.1.1+ Fix from $1,9502018-05-29 CRITICAL 9.8 CVE-2018-11523EPSS 10% upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. Nvrmini 2 Firmware after 3.6.5 Fix from $2,3002018-05-29 HIGH 8.8 CVE-2018-11514 PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated… Naukri Clone Script after 3.0.3 Fix from $1,9502018-05-28 CRITICAL 9.8 CVE-2018-6411EPSS 6% An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to … Machform No fix yet Fix from $2,3002018-05-26 HIGH 8.0 CVE-2018-11494 The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows att… Opencart after 3.0.2.0 Fix from $1,9502018-05-26 CRITICAL 9.8 CVE-2018-10648 There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. Xenmobile Server Mitigation only Fix from $2,3002018-05-23 HIGH 7.8 CVE-2017-2617 hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file… Hawtio 1.5.5+ Fix from $1,9502018-05-22 HIGH 7.5 CVE-2018-11322 An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by… Joomla\! 3.8.8+ Fix from $1,9502018-05-22 HIGH 7.2 CVE-2018-11340 An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified… As6202t Firmware No fix yet Fix from $1,9502018-05-22 HIGH 8.8 CVE-2018-11345 An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST param… As6202t Firmware No fix yet Fix from $1,9502018-05-22 CRITICAL 9.8 CVE-2018-11331 An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing s… Pluck 4.7.6+ Fix from $2,3002018-05-21 MEDIUM 6.1 CVE-2018-4921 Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to informat… Connect after 9.7 Fix from $1,6002018-05-19 HIGH 8.8 CVE-2018-10760 Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP… Projectpier after 0.8.8 Fix from $1,9502018-05-16 CRITICAL 9.8 CVE-2018-7505 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc… Webaccess 8.3.1+ Fix from $2,3002018-05-15 HIGH 7.2 CVE-2018-11098 An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CV… Frog Cms No fix yet Fix from $1,9502018-05-15 CRITICAL 9.9 CVE-2018-11091 An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker… Myprocurenet No fix yet Fix from $2,3002018-05-14 HIGH 8.8 CVE-2018-0568 Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated users to execute arbitrary PHP … Joruri Gw after 3.2.0 Fix from $1,9502018-05-14 CRITICAL 9.8 CVE-2018-10942EPSS 13% modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to exe… Attribute Wizard No fix yet Fix from $2,3002018-05-10 CRITICAL 9.8 CVE-2018-2420 SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi… Internet Graphics Server Mitigation only Fix from $2,3002018-05-09 HIGH 8.8 CVE-2018-10795 Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatica… Liferay Portal after 6.2.5 Fix from $1,9502018-05-07 CRITICAL 9.8 CVE-2018-0258EPSS 49% A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to a… Prime Data Center Network Manager Mitigation only Fix from $2,3002018-05-02 HIGH 8.8 CVE-2018-10577EPSS 7% An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.… Ap200 Firmware 1.2.9.15 / 2.0.0.10+ Fix from $1,9502018-05-02 CRITICAL 9.8 CVE-2016-10036EPSS 26% Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv… Artifactory 4.16+ Fix from $2,3002018-05-01 CRITICAL 9.8 CVE-2018-10469 b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI. Symphony No fix yet Fix from $2,3002018-04-27