Total
2929 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2013-3684 | 1 Imagely | 1 Nextgen Gallery | 2024-11-21 | 9.8 Critical |
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload | ||||
CVE-2013-3591 | 1 Vtiger | 1 Vtiger Crm | 2024-11-21 | 8.8 High |
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability | ||||
CVE-2013-2748 | 1 Belkin | 2 Wemo Switch, Wemo Switch Firmware | 2024-11-21 | 9.8 Critical |
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system. | ||||
CVE-2013-2057 | 1 Yabb | 1 Yabb | 2024-11-21 | 9.8 Critical |
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability | ||||
CVE-2013-20002 | 1 Themify | 1 Framework | 2024-11-21 | 9.8 Critical |
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file. | ||||
CVE-2013-1916 | 1 User Photo Project | 1 User Photo | 2024-11-21 | 8.8 High |
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved. | ||||
CVE-2013-0803 | 1 Polarbear Cms Project | 1 Polarbear Cms | 2024-11-21 | 9.8 Critical |
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. | ||||
CVE-2012-6649 | 1 Devfarm | 1 Wp Gpx Maps | 2024-11-21 | 9.8 Critical |
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload. | ||||
CVE-2012-5190 | 1 Accusoft | 1 Prizm Content Connect | 2024-11-21 | 9.8 Critical |
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability | ||||
CVE-2012-2950 | 2 Gatewaygeomatics, Microsoft | 2 Mapserver, Windows | 2024-11-21 | 8.1 High |
Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information. | ||||
CVE-2012-2226 | 1 Invisioncommunity | 1 Invision Power Board | 2024-11-21 | 9.8 Critical |
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file. | ||||
CVE-2012-1592 | 1 Apache | 1 Struts | 2024-11-21 | 8.8 High |
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. | ||||
CVE-2011-4908 | 1 Tiny | 1 Tinybrowser | 2024-11-21 | 9.8 Critical |
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | ||||
CVE-2011-4907 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 5.3 Medium |
Joomla! 1.5x through 1.5.12: Missing JEXEC Check | ||||
CVE-2011-4906 | 1 Tiny | 1 Tinybrowser | 2024-11-21 | 9.8 Critical |
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. | ||||
CVE-2011-4334 | 1 Labwiki Project | 1 Labwiki | 2024-11-21 | N/A |
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter. | ||||
CVE-2011-4183 | 1 Opensuse | 1 Open Build Service | 2024-11-21 | N/A |
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16. | ||||
CVE-2011-2933 | 1 Websitebaker | 1 Websitebaker | 2024-11-21 | 7.2 High |
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions. | ||||
CVE-2011-1597 | 1 Openvas | 1 Openvas Manager | 2024-11-21 | 8.8 High |
OpenVAS Manager v2.0.3 allows plugin remote code execution. | ||||
CVE-2011-1134 | 1 S9y | 1 Serendipity | 2024-11-21 | 9.8 Critical |
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager. |