Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-16524EPSS 30%
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote auth…
Web Viewer
No fix yet
HIGH 8.8
CVE-2017-10940EPSS 5%
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to [email protected].…
Triton Datacenter
Mitigation only
CRITICAL 9.8
CVE-2017-15990EPSS 8%
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
Phpinventory
No fix yet
HIGH 8.8
CVE-2017-15957
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
Ingenious School Management System
No fix yet
CRITICAL 9.8
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
Istock Management System
No fix yet
HIGH 8.8
CVE-2011-4334EPSS 6%
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP fil…
Labwiki
after 1.1
CRITICAL 9.8
CVE-2017-15580EPSS 16%
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's c…
Osticket
No fix yet
HIGH 8.8
CVE-2014-2664
Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine …
X2crm
after 3.7.5
CRITICAL 9.8
CVE-2015-2780EPSS 15%
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an execu…
Berta Cms
after 0.8.9b
HIGH 7.2
CVE-2017-1000119EPSS 61%
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applicatio…
October
No fix yet
HIGH 8.1
CVE-2017-12617 KEVEPSS 100%
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett…
Tomcat
7.0.82 / 8.0.47+
HIGH 8.8
CVE-2017-6090EPSS 96%
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrar…
Phpcollab
after 2.5.1
HIGH 7.2
CVE-2017-14958
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload…
Pivotx
Patch available
HIGH 8.8
CVE-2017-13982
A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows…
Bsm Platform Application Performance Management System Health
Mitigation only
HIGH 8.8
CVE-2017-14838
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
Job Links
No fix yet
HIGH 8.8
CVE-2017-14839
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
Photo Fusion
No fix yet
HIGH 8.8
CVE-2017-14840
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
Ticketplus
No fix yet
MEDIUM 6.5
CVE-2017-14841
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
Annual Maintenance Contract Management System
No fix yet
CRITICAL 9.8
CVE-2015-8249EPSS 74%
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via th…
Desktop Central
Patch available
HIGH 8.8
CVE-2017-14704EPSS 8%
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow rem…
Airbnb Clone
No fix yet
HIGH 8.8
CVE-2017-14079EPSS 11%
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on…
Mobile Security
Patch available
HIGH 8.8
CVE-2017-12929EPSS 10%
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files lea…
Dlx Spot Player4
No fix yet
HIGH 7.2
CVE-2014-9619EPSS 7%
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x bef…
Netsweeper
after 3.1.9
HIGH 8.1
CVE-2017-12615 KEVEPSS 100%
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t…
Tomcat
after 7.0.79
CRITICAL 9.8
CVE-2017-1002000EPSS 27%
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/i…
Mobile Friendly App Builder By Easytouch
No fix yet
CRITICAL 9.8
CVE-2017-1002001EPSS 11%
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedi…
Mobile App Builder By Wappress
No fix yet
CRITICAL 9.8
CVE-2017-1002002EPSS 13%
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
Webapp Builder
No fix yet
CRITICAL 9.8
CVE-2017-1002003EPSS 12%
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http:/…
Wp2android Turn Wp Site Into Android App
No fix yet
CRITICAL 9.8
CVE-2017-1002008EPSS 17%
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-memb…
Membership Simplified
No fix yet
CRITICAL 9.8
CVE-2017-1002016
Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticat…
Flickr Picture Backup
No fix yet