Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2018-6860 Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a profile picture. Schools Alert Management Script No fix yet Fix from $1,9502018-02-12 CRITICAL 9.8 CVE-2018-6580EPSS 36% Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request. Jimtawl No fix yet Fix from $2,3002018-02-02 CRITICAL 9.8 CVE-2017-17976EPSS 13% In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. Perfex Crm No fix yet Fix from $2,3002018-01-26 HIGH 8.8 CVE-2017-14521EPSS 7% In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. Wondercms No fix yet Fix from $1,9502018-01-26 CRITICAL 9.8 CVE-2018-1342 A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts Ne… Access Manager Mitigation only Fix from $2,3002018-01-26 CRITICAL 9.8 CVE-2018-5997EPSS 24% An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, i… Filehub Firmware No fix yet Fix from $2,3002018-01-25 CRITICAL 9.8 CVE-2018-4834 A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PX… Pxc12\/22\/36 E.d Firmware 6.00.204+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2018-5749 install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before savin… Premium Minecraft Servers List 1.1 / 2.0.4+ Fix from $2,3002018-01-23 HIGH 8.8 CVE-2017-18048EPSS 63% Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase)… Monstra Patch available Fix from $1,9502018-01-23 MEDIUM 6.5 CVE-2017-16594 This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build … Enterprise Manager Mitigation only Fix from $1,6002018-01-23 CRITICAL 9.8 CVE-2018-5724EPSS 12% MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi. Master Ip Camera01 Firmware No fix yet Fix from $2,3002018-01-16 HIGH 7.5 CVE-2017-16736 An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attac… Webaccess 8.3+ Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2014-4972 Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary c… Ajax Upload For Gravity Forms after 1.1 Fix from $2,3002018-01-08 HIGH 8.8 CVE-2017-15549EPSS 6% An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte… Avamar Server Mitigation only Fix from $1,9502018-01-05 HIGH 8.8 CVE-2018-3814 Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option,… Craft Cms No fix yet Fix from $1,9502018-01-01 HIGH 7.2 CVE-2017-17987 PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php. Muslim Matrimonial Script No fix yet Fix from $1,9502017-12-30 HIGH 8.8 CVE-2017-17874EPSS 6% Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can ma… Marketplace Digital Products Php No fix yet Fix from $1,9502017-12-27 HIGH 7.2 CVE-2017-15876 Unrestricted File Upload vulnerability in GPWeb 8.4.61 allows remote authenticated users to upload any type of file, including a PHP shell. Gpweb No fix yet Fix from $1,9502017-12-19 CRITICAL 9.8 CVE-2017-16949EPSS 19% An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the a… Anonymous Post Pro after 3.1.9 Fix from $2,3002017-12-19 HIGH 8.8 CVE-2017-17727 DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parame… Dedecms after 5.6 Fix from $1,9502017-12-18 HIGH 7.5 CVE-2017-17593EPSS 6% Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/. Simple Chatting System No fix yet Fix from $1,9502017-12-13 HIGH 7.8 CVE-2017-13156EPSS 20% An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android I… Android Patch available Fix from $1,9502017-12-06 HIGH 7.2 CVE-2017-15673 The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a … Cs Cart after 4.6.2 Fix from $1,9502017-11-28 HIGH 7.5 CVE-2017-15054 An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to R… Teampass 2.1.27.9+ Fix from $1,9502017-11-27 HIGH 8.8 CVE-2017-16941 October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by dow… October after 1.0.428 Fix from $1,9502017-11-25 HIGH 8.8 CVE-2017-2737 VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files … Vcm5010 Firmware Mitigation only Fix from $1,9502017-11-22 HIGH 7.8 CVE-2017-2699 The Huawei Themes APP in versions earlier than PLK-UL00C17B385, versions earlier than CRR-L09C432B380, versions earlier than LYO-L21C577B128 has a pr… Honor 7 Firmware Mitigation only Fix from $1,9502017-11-22 CRITICAL 9.8 CVE-2017-8862 The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted … 3960hd Firmware Mitigation only Fix from $2,3002017-11-22 HIGH 8.8 CVE-2017-1000238 InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver.… Invoiceplane No fix yet Fix from $1,9502017-11-17 CRITICAL 9.8 CVE-2017-1000194 October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly othe… October after 1.0.412 Fix from $2,3002017-11-17