Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-12051
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as …
Schools Alert Management Script
No fix yet
CRITICAL 9.8
CVE-2018-12045
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfi…
Dedecms
5.7+
HIGH 8.8
CVE-2018-3758EPSS 27%
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
Express Cart
1.1.7+
HIGH 7.2
CVE-2018-1265
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF a…
Cf Deployment
1.37.0 / 2.8.0+
CRITICAL 9.8
CVE-2018-11736EPSS 9%
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using th…
Pluck
after 4.7.7
HIGH 7.5
CVE-2018-11196
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files int…
Mahara
17.04.8 / 17.10.5+
HIGH 8.8
CVE-2018-11392
An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the En…
Php Login \& User Management
4.1.1+
CRITICAL 9.8
CVE-2018-11523EPSS 10%
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
Nvrmini 2 Firmware
after 3.6.5
HIGH 8.8
CVE-2018-11514
PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated…
Naukri Clone Script
after 3.0.3
CRITICAL 9.8
CVE-2018-6411EPSS 6%
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to …
Machform
No fix yet
HIGH 8.0
CVE-2018-11494
The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows att…
Opencart
after 3.0.2.0
CRITICAL 9.8
CVE-2018-10648
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Xenmobile Server
Mitigation only
HIGH 7.8
CVE-2017-2617
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file…
Hawtio
1.5.5+
HIGH 7.5
CVE-2018-11322
An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by…
Joomla\!
3.8.8+
HIGH 7.2
CVE-2018-11340
An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified…
As6202t Firmware
No fix yet
HIGH 8.8
CVE-2018-11345
An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST param…
As6202t Firmware
No fix yet
CRITICAL 9.8
CVE-2018-11331
An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing s…
Pluck
4.7.6+
MEDIUM 6.1
CVE-2018-4921
Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to informat…
Connect
after 9.7
HIGH 8.8
CVE-2018-10760
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP…
Projectpier
after 0.8.8
CRITICAL 9.8
CVE-2018-7505
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…
Webaccess
8.3.1+
HIGH 7.2
CVE-2018-11098
An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CV…
Frog Cms
No fix yet
CRITICAL 9.9
CVE-2018-11091
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker…
Myprocurenet
No fix yet
HIGH 8.8
CVE-2018-0568
Unrestricted file upload vulnerability in SiteBridge Inc. Joruri Gw Ver 3.2.0 and earlier allows remote authenticated users to execute arbitrary PHP …
Joruri Gw
after 3.2.0
CRITICAL 9.8
CVE-2018-10942EPSS 13%
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to exe…
Attribute Wizard
No fix yet
CRITICAL 9.8
CVE-2018-2420
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper fi…
Internet Graphics Server
Mitigation only
HIGH 8.8
CVE-2018-10795
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatica…
Liferay Portal
after 6.2.5
CRITICAL 9.8
CVE-2018-0258EPSS 49%
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to a…
Prime Data Center Network Manager
Mitigation only
HIGH 8.8
CVE-2018-10577EPSS 7%
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.…
Ap200 Firmware
1.2.9.15 / 2.0.0.10+
CRITICAL 9.8
CVE-2016-10036EPSS 26%
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary serv…
Artifactory
4.16+
CRITICAL 9.8
CVE-2018-10469
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.
Symphony
No fix yet