Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2017-14399 In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing… Blackcat Cms Mitigation only Fix from $1,9502017-09-12 CRITICAL 9.8 CVE-2017-14346 upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png… Blog after 2017-09-12 Fix from $2,3002017-09-12 HIGH 8.8 CVE-2015-9228 In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a fil… Nextgen Gallery No fix yet Fix from $1,9502017-09-12 HIGH 8.8 CVE-2017-14251 Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8… TYPO3 No fix yet Fix from $1,9502017-09-11 HIGH 8.8 CVE-2017-14123EPSS 6% Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with a… Manageengine Firewall Analyzer Patch available Fix from $1,9502017-09-04 HIGH 8.8 CVE-2017-14050 In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .ph… Blackcat Cms Mitigation only Fix from $1,9502017-08-31 CRITICAL 9.8 CVE-2013-7426 Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1. Kamailio Patch available Fix from $2,3002017-08-29 MEDIUM 5.5 CVE-2016-0354 IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that co… Sametime Patch available Fix from $1,6002017-08-29 HIGH 8.8 CVE-2014-9312EPSS 45% Unrestricted File Upload vulnerability in Photo Gallery 1.2.5. Photo Gallery No fix yet Fix from $1,9502017-08-28 HIGH 7.8 CVE-2017-9650 An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and … I Vu after 6.5 Fix from $1,9502017-08-25 CRITICAL 9.8 CVE-2017-11357 KEVEPSS 76% Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to per… Telerik Ui For Asp.net Ajax 2020.1.114+ Fix from $2,3002017-08-23 CRITICAL 9.8 CVE-2017-3108EPSS 9% Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability. Experience Manager after 6.2 Fix from $2,3002017-08-11 HIGH 7.2 CVE-2017-11154EPSS 9% Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to … Photo Station after 6.7.2-3429 Fix from $1,9502017-08-08 HIGH 8.8 CVE-2017-12678 In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to … Debian Linux Patch available Fix from $1,9502017-08-08 HIGH 7.8 CVE-2015-7571EPSS 8% Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable e… Yeager Cms No fix yet Fix from $1,9502017-08-07 HIGH 7.0 CVE-2017-11756 In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload exte… Ear Music after 4.1 Fix from $1,9502017-07-30 MEDIUM 6.5 CVE-2015-4462 Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary… Efront after 3.6.15.4 Fix from $1,6002017-07-25 MEDIUM 6.5 CVE-2015-4463 The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a… Efront after 3.6.15.4 Fix from $1,6002017-07-25 HIGH 7.5 CVE-2017-11326 An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipu… Tilde Cms No fix yet Fix from $1,9502017-07-24 HIGH 7.2 CVE-2017-11466EPSS 8% Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrato… Dotcms Patch available Fix from $1,9502017-07-20 CRITICAL 9.8 CVE-2017-1000081 Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution. Onos Mitigation only Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-6041 An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, … A320 Firmware Mitigation only Fix from $2,3002017-06-30 HIGH 8.8 CVE-2017-9840 Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within t… Dolibarr after 5.0.3 Fix from $1,9502017-06-25 CRITICAL 9.8 CVE-2017-4990 In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of … Avamar Server Mitigation only Fix from $2,3002017-06-21 HIGH 8.8 CVE-2017-9380EPSS 15% OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context… Openemr after 5.0.0 Fix from $1,9502017-06-02 CRITICAL 9.8 CVE-2017-9364 Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety ch… Bigtree Cms after 4.2.18 Fix from $2,3002017-06-02 CRITICAL 9.8 CVE-2015-4455EPSS 41% Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allow… Aviary Image Editor Add On For Gravity Forms after 3.0 Fix from $2,3002017-05-23 CRITICAL 9.8 CVE-2017-9101EPSS 77% import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP co… Playsms No fix yet Fix from $2,3002017-05-21 HIGH 8.8 CVE-2017-9080EPSS 62% PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unr… Playsms No fix yet Fix from $1,9502017-05-19 CRITICAL 9.8 CVE-2017-6027 An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, p… Web Server after 2.3 Fix from $2,3002017-05-19