Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-10375
A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and exe…
Dedecms
Mitigation only
HIGH 8.8
CVE-2018-10173EPSS 5%
Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.
Management Console
No fix yet
HIGH 7.2
CVE-2018-9153
The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppC…
Z Blogphp
Mitigation only
MEDIUM 6.8
CVE-2016-10258
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administr…
Advanced Secure Gateway
6.5.10.8 / 6.6.5.14+
HIGH 8.8
CVE-2018-9037
Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php file…
Monstra
No fix yet
CRITICAL 9.8
CVE-2018-2404
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
Disclosure Management
Mitigation only
HIGH 7.5
CVE-2018-9156
An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacke…
P1354 Firmware
No fix yet
HIGH 7.5
CVE-2018-9157
An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attac…
M1033 W Firmware
Mitigation only
CRITICAL 9.8
CVE-2015-9259
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating tha…
Notary
0.1+
CRITICAL 9.8
CVE-2018-8944
PHPOK 4.8.338 has an arbitrary file upload vulnerability.
Phpok
No fix yet
HIGH 8.8
CVE-2017-16772
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote…
Photo Station
6.3-2971 / 6.8.3-3463+
CRITICAL 9.8
CVE-2014-4912EPSS 8%
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
Frog Cms
No fix yet
CRITICAL 9.8
CVE-2018-8766
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.p…
Joyplus Cms
No fix yet
HIGH 8.8
CVE-2017-16251
A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious scr…
St14.2
Mitigation only
HIGH 7.2
CVE-2018-1000094EPSS 39%
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that ha…
Cms Made Simple
No fix yet
HIGH 7.5
CVE-2018-7562
A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable …
Glpi
after 9.2.1
CRITICAL 9.8
CVE-2014-2592
Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an e…
Web Management Portal
Mitigation only
HIGH 8.8
CVE-2018-1215
An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, D…
Emc Solutions Enabler Virtual Appliance
8.4.0.18 / 8.4.0.21+
CRITICAL 9.8
CVE-2016-7443
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
Exponent Cms
after 2.3.9
CRITICAL 9.8
CVE-2018-7665EPSS 16%
An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.ph…
Clipbucket
after 4.0.0
HIGH 7.2
CVE-2018-7567EPSS 5%
In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to expl…
Otrs
after 5.0.23
HIGH 7.8
CVE-2015-0796
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files l…
Open Buildservice
2.4.8 / 2.5.7+
HIGH 8.8
CVE-2017-7429
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authen…
Edirectory
after 8.8.8
HIGH 7.2
CVE-2017-9279
NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Applicat…
Identity Manager
4.5.6.1+
MEDIUM 6.5
CVE-2017-6931
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not…
Drupal
8.4.5+
CRITICAL 9.8
CVE-2018-7316EPSS 8%
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
Proclaim
No fix yet
HIGH 8.8
CVE-2018-7217
In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or the server side. An attacker…
Bravo Solution
No fix yet
HIGH 8.8
CVE-2016-8515
A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.…
Version Control Repository Manager
7.6+
HIGH 8.8
CVE-2017-1499
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary…
Maximo Asset Management
Patch available
HIGH 7.2
CVE-2017-9970
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains care…
Struxureon Gateway
after 1.1.3