Vulnerabilities (CVE)

Filtered by CWE-434
Total 4073 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10036 1 Jfrog 1 Artifactory 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
CVE-2016-0354 1 Ibm 1 Sametime 2026-06-17 6.0 MEDIUM 5.5 MEDIUM
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.
CVE-2015-9499 1 Themepunch 1 Showbiz Pro 2026-06-17 7.5 HIGH 9.8 CRITICAL
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
CVE-2015-9479 1 Advancedcustomfields 1 Acf Fronted Display 2026-06-17 7.5 HIGH 9.8 CRITICAL
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
CVE-2015-9471 1 Digitalzoomstudio 1 Zoomsounds 2026-06-17 7.5 HIGH 9.8 CRITICAL
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
CVE-2015-9402 1 Usersultra 1 Users Ultra Membership 2026-06-17 6.8 MEDIUM 8.8 HIGH
The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
CVE-2015-9341 1 Iptanus 1 Wordpress File Upload 2026-06-17 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
CVE-2015-9340 1 Iptanus 1 Wordpress File Upload 2026-06-17 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
CVE-2015-9339 1 Iptanus 1 Wordpress File Upload 2026-06-17 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
CVE-2015-9338 1 Iptanus 1 Wordpress File Upload 2026-06-17 5.0 MEDIUM 7.5 HIGH
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
CVE-2015-9271 1 Videowhisper 1 Video Conference 2026-06-17 7.5 HIGH 9.8 CRITICAL
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905.
CVE-2015-9263 1 Idera 1 Uptime Infrastructure Monitor 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
CVE-2015-9259 1 Docker 1 Notary 2026-06-17 7.5 HIGH 9.8 CRITICAL
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file.
CVE-2015-9228 1 Imagely 1 Nextgen Gallery 2026-06-17 9.0 HIGH 8.8 HIGH
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
CVE-2015-8249 1 Manageengine 1 Desktop Central 2026-06-17 10.0 HIGH 9.8 CRITICAL
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
CVE-2015-7571 1 Yeager 1 Yeager Cms 2026-06-17 6.8 MEDIUM 7.8 HIGH
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
CVE-2015-7341 1 Joobi 1 Jnews 2026-06-17 6.5 MEDIUM 8.8 HIGH
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
CVE-2015-7339 1 Widgetfactorylimited 1 Jce 2026-06-17 6.5 MEDIUM 8.8 HIGH
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
CVE-2015-6000 1 Vtiger 1 Vtiger Crm 2026-06-17 6.5 MEDIUM 8.8 HIGH
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in test/logo/.
CVE-2015-5951 1 Thomsonreuters 1 Fatca 2026-06-17 9.0 HIGH 9.9 CRITICAL
A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.