Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2018-10375 A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and exe… Dedecms Mitigation only Fix from $2,3002018-04-25 HIGH 8.8 CVE-2018-10173EPSS 5% Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality. Management Console No fix yet Fix from $1,9502018-04-20 HIGH 7.2 CVE-2018-9153 The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppC… Z Blogphp Mitigation only Fix from $1,9502018-04-16 MEDIUM 6.8 CVE-2016-10258 Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administr… Advanced Secure Gateway 6.5.10.8 / 6.6.5.14+ Fix from $1,6002018-04-11 HIGH 8.8 CVE-2018-9037 Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php file… Monstra No fix yet Fix from $1,9502018-04-10 CRITICAL 9.8 CVE-2018-2404 SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation. Disclosure Management Mitigation only Fix from $2,3002018-04-10 HIGH 7.5 CVE-2018-9156 An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacke… P1354 Firmware No fix yet Fix from $1,9502018-04-01 HIGH 7.5 CVE-2018-9157 An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attac… M1033 W Firmware Mitigation only Fix from $1,9502018-04-01 CRITICAL 9.8 CVE-2015-9259 In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating tha… Notary 0.1+ Fix from $2,3002018-03-31 CRITICAL 9.8 CVE-2018-8944 PHPOK 4.8.338 has an arbitrary file upload vulnerability. Phpok No fix yet Fix from $2,3002018-03-22 HIGH 8.8 CVE-2017-16772 Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote… Photo Station 6.3-2971 / 6.8.3-3463+ Fix from $1,9502018-03-22 CRITICAL 9.8 CVE-2014-4912EPSS 8% An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. Frog Cms No fix yet Fix from $2,3002018-03-22 CRITICAL 9.8 CVE-2018-8766 joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.p… Joyplus Cms No fix yet Fix from $2,3002018-03-18 HIGH 8.8 CVE-2017-16251 A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious scr… St14.2 Mitigation only Fix from $1,9502018-03-13 HIGH 7.2 CVE-2018-1000094EPSS 39% CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that ha… Cms Made Simple No fix yet Fix from $1,9502018-03-13 HIGH 7.5 CVE-2018-7562 A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable … Glpi after 9.2.1 Fix from $1,9502018-03-12 CRITICAL 9.8 CVE-2014-2592 Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an e… Web Management Portal Mitigation only Fix from $2,3002018-03-09 HIGH 8.8 CVE-2018-1215 An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, D… Emc Solutions Enabler Virtual Appliance 8.4.0.18 / 8.4.0.21+ Fix from $1,9502018-03-08 CRITICAL 9.8 CVE-2016-7443 Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location." Exponent Cms after 2.3.9 Fix from $2,3002018-03-07 CRITICAL 9.8 CVE-2018-7665EPSS 16% An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.ph… Clipbucket after 4.0.0 Fix from $2,3002018-03-05 HIGH 7.2 CVE-2018-7567EPSS 5% In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to expl… Otrs after 5.0.23 Fix from $1,9502018-03-04 HIGH 7.8 CVE-2015-0796 In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l… Open Buildservice 2.4.8 / 2.5.7+ Fix from $1,9502018-03-02 HIGH 8.8 CVE-2017-7429 The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authen… Edirectory after 8.8.8 Fix from $1,9502018-03-02 HIGH 7.2 CVE-2017-9279 NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Applicat… Identity Manager 4.5.6.1+ Fix from $1,9502018-03-02 MEDIUM 6.5 CVE-2017-6931 In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not… Drupal 8.4.5+ Fix from $1,6002018-03-01 CRITICAL 9.8 CVE-2018-7316EPSS 8% Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. Proclaim No fix yet Fix from $2,3002018-02-22 HIGH 8.8 CVE-2018-7217 In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or the server side. An attacker… Bravo Solution No fix yet Fix from $1,9502018-02-18 HIGH 8.8 CVE-2016-8515 A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.… Version Control Repository Manager 7.6+ Fix from $1,9502018-02-15 HIGH 8.8 CVE-2017-1499 IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary… Maximo Asset Management Patch available Fix from $1,9502018-02-14 HIGH 7.2 CVE-2017-9970 A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains care… Struxureon Gateway after 1.1.3 Fix from $1,9502018-02-12