Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-14399
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing…
Blackcat Cms
Mitigation only
CRITICAL 9.8
CVE-2017-14346
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png…
Blog
after 2017-09-12
HIGH 8.8
CVE-2015-9228
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a fil…
Nextgen Gallery
No fix yet
HIGH 8.8
CVE-2017-14251
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8…
TYPO3
No fix yet
HIGH 8.8
CVE-2017-14123EPSS 6%
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with a…
Manageengine Firewall Analyzer
Patch available
HIGH 8.8
CVE-2017-14050
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .ph…
Blackcat Cms
Mitigation only
CRITICAL 9.8
CVE-2013-7426
Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.
Kamailio
Patch available
MEDIUM 5.5
CVE-2016-0354
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that co…
Sametime
Patch available
HIGH 8.8
CVE-2014-9312EPSS 45%
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
Photo Gallery
No fix yet
HIGH 7.8
CVE-2017-9650
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and …
I Vu
after 6.5
CRITICAL 9.8
CVE-2017-11357 KEVEPSS 76%
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to per…
Telerik Ui For Asp.net Ajax
2020.1.114+
CRITICAL 9.8
CVE-2017-3108EPSS 9%
Adobe Experience Manager 6.2 and earlier has a malicious file execution vulnerability.
Experience Manager
after 6.2
HIGH 7.2
CVE-2017-11154EPSS 9%
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to …
Photo Station
after 6.7.2-3429
HIGH 8.8
CVE-2017-12678
In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to …
Debian Linux
Patch available
HIGH 7.8
CVE-2015-7571EPSS 8%
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable e…
Yeager Cms
No fix yet
HIGH 7.0
CVE-2017-11756
In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload exte…
Ear Music
after 4.1
MEDIUM 6.5
CVE-2015-4462
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary…
Efront
after 3.6.15.4
MEDIUM 6.5
CVE-2015-4463
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a…
Efront
after 3.6.15.4
HIGH 7.5
CVE-2017-11326
An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipu…
Tilde Cms
No fix yet
HIGH 7.2
CVE-2017-11466EPSS 8%
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrato…
Dotcms
Patch available
CRITICAL 9.8
CVE-2017-1000081
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
Onos
Mitigation only
CRITICAL 9.8
CVE-2017-6041
An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, …
A320 Firmware
Mitigation only
HIGH 8.8
CVE-2017-9840
Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within t…
Dolibarr
after 5.0.3
CRITICAL 9.8
CVE-2017-4990
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of …
Avamar Server
Mitigation only
HIGH 8.8
CVE-2017-9380EPSS 15%
OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context…
Openemr
after 5.0.0
CRITICAL 9.8
CVE-2017-9364
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety ch…
Bigtree Cms
after 4.2.18
CRITICAL 9.8
CVE-2015-4455EPSS 41%
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allow…
Aviary Image Editor Add On For Gravity Forms
after 3.0
CRITICAL 9.8
CVE-2017-9101EPSS 77%
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP co…
Playsms
No fix yet
HIGH 8.8
CVE-2017-9080EPSS 62%
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unr…
Playsms
No fix yet
CRITICAL 9.8
CVE-2017-6027
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, p…
Web Server
after 2.3