Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2017-16524EPSS 30% Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote auth… Web Viewer No fix yet Fix from $1,9502017-11-06 HIGH 8.8 CVE-2017-10940EPSS 5% This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to [email protected].… Triton Datacenter Mitigation only Fix from $1,9502017-10-31 CRITICAL 9.8 CVE-2017-15990EPSS 8% Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. Phpinventory No fix yet Fix from $2,3002017-10-31 HIGH 8.8 CVE-2017-15957 my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file. Ingenious School Management System No fix yet Fix from $1,9502017-10-29 CRITICAL 9.8 CVE-2017-15962 iStock Management System 1.0 allows Arbitrary File Upload via user/profile. Istock Management System No fix yet Fix from $2,3002017-10-29 HIGH 8.8 CVE-2011-4334EPSS 6% edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP fil… Labwiki after 1.1 Fix from $1,9502017-10-23 CRITICAL 9.8 CVE-2017-15580EPSS 16% osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's c… Osticket No fix yet Fix from $2,3002017-10-23 HIGH 8.8 CVE-2014-2664 Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine … X2crm after 3.7.5 Fix from $1,9502017-10-17 CRITICAL 9.8 CVE-2015-2780EPSS 15% Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an execu… Berta Cms after 0.8.9b Fix from $2,3002017-10-16 HIGH 7.2 CVE-2017-1000119EPSS 61% October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applicatio… October No fix yet Fix from $1,9502017-10-05 HIGH 8.1 CVE-2017-12617 KEVEPSS 100% When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via sett… Tomcat 7.0.82 / 8.0.47+ Fix from $1,9502017-10-04 HIGH 8.8 CVE-2017-6090EPSS 96% Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrar… Phpcollab after 2.5.1 Fix from $1,9502017-10-03 HIGH 7.2 CVE-2017-14958 lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload… Pivotx Patch available Fix from $1,9502017-10-02 HIGH 8.8 CVE-2017-13982 A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows… Bsm Platform Application Performance Management System Health Mitigation only Fix from $1,9502017-09-30 HIGH 8.8 CVE-2017-14838 TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. Job Links No fix yet Fix from $1,9502017-09-28 HIGH 8.8 CVE-2017-14839 TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. Photo Fusion No fix yet Fix from $1,9502017-09-28 HIGH 8.8 CVE-2017-14840 TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. Ticketplus No fix yet Fix from $1,9502017-09-28 MEDIUM 6.5 CVE-2017-14841 Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling. Annual Maintenance Contract Management System No fix yet Fix from $1,6002017-09-28 CRITICAL 9.8 CVE-2015-8249EPSS 74% The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via th… Desktop Central Patch available Fix from $2,3002017-09-28 HIGH 8.8 CVE-2017-14704EPSS 8% Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow rem… Airbnb Clone No fix yet Fix from $1,9502017-09-26 HIGH 8.8 CVE-2017-14079EPSS 11% Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on… Mobile Security Patch available Fix from $1,9502017-09-22 HIGH 8.8 CVE-2017-12929EPSS 10% Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files lea… Dlx Spot Player4 No fix yet Fix from $1,9502017-09-21 HIGH 7.2 CVE-2014-9619EPSS 7% Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x bef… Netsweeper after 3.1.9 Fix from $1,9502017-09-19 HIGH 8.1 CVE-2017-12615 KEVEPSS 100% When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default t… Tomcat after 7.0.79 Fix from $1,9502017-09-19 CRITICAL 9.8 CVE-2017-1002000EPSS 27% Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/i… Mobile Friendly App Builder By Easytouch No fix yet Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-1002001EPSS 11% Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedi… Mobile App Builder By Wappress No fix yet Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-1002002EPSS 13% Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/ Webapp Builder No fix yet Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-1002003EPSS 12% Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http:/… Wp2android Turn Wp Site Into Android App No fix yet Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-1002008EPSS 17% Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-memb… Membership Simplified No fix yet Fix from $2,3002017-09-14 CRITICAL 9.8 CVE-2017-1002016 Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticat… Flickr Picture Backup No fix yet Fix from $2,3002017-09-14