Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2017-9069 In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess. Modx Revolution after 2.5.6 Fix from $1,9502017-05-18 HIGH 8.8 CVE-2017-8080 Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving im… Hipchat Server after 2.2.3 Fix from $1,9502017-05-05 MEDIUM 6.5 CVE-2017-7989 In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explic… Joomla\! Patch available Fix from $1,6002017-04-25 CRITICAL 9.1 CVE-2017-7357 Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a fil… Hipchat Server after 2.2.2 Fix from $2,3002017-04-14 HIGH 7.3 CVE-2016-1713EPSS 17% Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.p… Vtiger Crm No fix yet Fix from $1,9502017-04-14 HIGH 8.8 CVE-2017-7281 An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport func… Enterprise Backup after 9.1.1 Fix from $1,9502017-04-12 CRITICAL 9.8 CVE-2017-7695 Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and e… Bigtree Cms after 4.2.16 Fix from $2,3002017-04-11 HIGH 8.8 CVE-2015-3884EPSS 14% Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6) reports, and (7) scheduler pa… Qdpm after 9.1 Fix from $1,9502017-03-17 HIGH 7.5 CVE-2017-6104EPSS 7% Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. Zen Mobile App Native after 3.0 Fix from $1,9502017-03-02 HIGH 7.2 CVE-2016-6104 IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file exte… Security Key Lifecycle Manager Patch available Fix from $1,9502017-02-07 HIGH 8.8 CVE-2016-6124 IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arb… Kenexa Lms On Cloud Mitigation only Fix from $1,9502017-02-01 HIGH 8.8 CVE-2016-8921 IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vul… Filenet Workplace Xt Mitigation only Fix from $1,9502017-02-01 HIGH 8.8 CVE-2017-5520 The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, wh… Genixcms after 0.0.8 Fix from $1,9502017-01-17 HIGH 8.8 CVE-2016-7902 Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to… Dotclear after 2.10.2 Fix from $1,9502017-01-04 HIGH 7.2 CVE-2016-9268EPSS 5% Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote au… Dotclear after 2.10.4 Fix from $1,9502016-11-10 HIGH 8.8 CVE-2016-9187 Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to exe… Moodle after 3.1.2 Fix from $1,9502016-11-04 HIGH 8.8 CVE-2016-9186 Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to e… Moodle after 3.1.2 Fix from $1,9502016-11-04 HIGH 7.5 CVE-2016-7452 The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directo… Exponent Cms after 2.3.9 Fix from $1,9502016-11-03 CRITICAL 9.8 CVE-2016-7095 Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected fold… Exponent Cms after 2.3.8 Fix from $2,3002016-11-03 HIGH 7.8 CVE-2015-1000013 Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1 Csv2wpec Coupon No fix yet Fix from $1,9502016-10-06 CRITICAL 9.8 CVE-2015-1000001 Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin Fast Image Adder after 1.1 Fix from $2,3002016-10-06 CRITICAL 9.8 CVE-2015-1000000 Remote file upload vulnerability in mailcwp v1.99 wordpress plugin Mailcwp No fix yet Fix from $2,3002016-10-06 CRITICAL 9.8 CVE-2016-5050 Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requ… Readydesk Mitigation only Fix from $2,3002016-08-26 MEDIUM 5.4 CVE-2016-2914 Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authe… Engineering Lifecycle Optimization Publishing Patch available Fix from $1,6002016-08-08 CRITICAL 9.8 CVE-2016-3088 KEVEPSS 99% The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol… Activemq 5.14.0+ Fix from $2,3002016-06-01 MEDIUM 6.5 CVE-2015-4524 Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.… Documentum Administrator Mitigation only Fix from $1,6002015-07-04 HIGH 9.0 CVE-2015-0702 Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated… Unified Meetingplace Mitigation only Fix from $1,9502015-04-21 MEDIUM 6.4 CVE-2006-6994 Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitr… Ozzywork Galeri after 2.0 Fix from $1,6002007-02-12 MEDIUM 6.5 CVE-2006-5845 Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by s… Speedywiki Mitigation only Fix from $1,6002006-11-10 HIGH 7.5 CVE-2006-4558 DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uplo… Deluxebb after 1.06 Fix from $1,9502006-09-06