Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Secure Firewall Management Center HIGH 8.8
CVE-2022-20743

A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to …

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Import Wp HIGH 7.2
CVE-2022-1273

The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload …

Fix: 2.4.6+
Fix from $1,950 2022-05-02
Rara One Click Demo Import HIGH 8.8
CVE-2022-29451

Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows at…

Fix: 1.3.0+
Fix from $1,950 2022-04-29
Smartptt Scada CRITICAL 9.8
CVE-2021-43934

Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentia…

Mitigation only
Fix from $2,300 2022-04-28
Novel Plus CRITICAL 9.8
CVE-2021-41921

novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.

No fix yet
Fix from $2,300 2022-04-28
Ed01 Cms HIGH 8.8
CVE-2022-28525

ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.

Mitigation only
Fix from $1,950 2022-04-26
Bloofoxcms HIGH 8.8
CVE-2022-28528

bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

No fix yet
Fix from $1,950 2022-04-26
Maxboard MEDIUM 6.1
CVE-2021-26628

Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a spe…

Fix: 1.9.6.1+
Fix from $1,600 2022-04-26
Monsta Ftp CRITICAL 9.8
CVE-2022-27468

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to …

No fix yet
Fix from $2,300 2022-04-26
Planning Analytics Workspace HIGH 7.8
CVE-2022-22392

IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could re…

Mitigation only
Fix from $1,950 2022-04-25
Planning Analytics Workspace HIGH 8.0
CVE-2021-39040

IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use o…

Mitigation only
Fix from $1,950 2022-04-25
Sp Project \& Document Manager HIGH 8.8
CVE-2021-4225

The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attem…

Fix: 4.24+
Fix from $1,950 2022-04-25
Typemill HIGH 8.8
CVE-2022-28053

Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to exec…

No fix yet
Fix from $1,950 2022-04-25
Ucms HIGH 8.8
CVE-2022-28440

An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2022-04-21
Purchase Order Management System CRITICAL 9.8
CVE-2022-28021EPSS 24%

Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.

No fix yet
Fix from $2,300 2022-04-21
Victor Cms HIGH 8.8
CVE-2022-27478EPSS 20%

Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.

No fix yet
Fix from $1,950 2022-04-21
Vikbooking Hotel Booking Engine \& Property Management System Plugin CRITICAL 9.8
CVE-2022-27862

Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and …

Fix: after 1.5.3
Fix from $2,300 2022-04-19
Fancy Product Designer HIGH 8.8
CVE-2021-4096

The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for…

Fix: after 4.7.5
Fix from $1,950 2022-04-19
Website Builder HIGH 8.8
CVE-2022-1329EPSS 93%

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check …

Fix: after 3.6.2
Fix from $1,950 2022-04-19
Organizr CRITICAL 9.0
CVE-2022-1345

Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the u…

Fix: 2.1.1810+
Fix from $2,300 2022-04-13
Skipper CRITICAL 9.8
CVE-2022-27262

An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.

Mitigation only
Fix from $2,300 2022-04-12
Strapi CRITICAL 9.8
CVE-2022-27263

An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $2,300 2022-04-12
Payload CRITICAL 9.8
CVE-2022-27952

An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG f…

No fix yet
Fix from $2,300 2022-04-12
Ghost CRITICAL 9.8
CVE-2022-28397

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. …

Mitigation only
Fix from $2,300 2022-04-12
Ghost CRITICAL 9.8
CVE-2022-27139

An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. …

No fix yet
Fix from $2,300 2022-04-12
Express Fileupload CRITICAL 9.8
CVE-2022-27140

An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted…

No fix yet
Fix from $2,300 2022-04-12
Buttercms CRITICAL 9.8
CVE-2022-27260

An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG …

Mitigation only
Fix from $2,300 2022-04-12
Express Fileupload HIGH 7.5
CVE-2022-27261

An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite…

No fix yet
Fix from $1,950 2022-04-12
Hedgedoc MEDIUM 5.3
CVE-2022-24837

HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enum…

Fix: 1.9.3+
Fix from $1,600 2022-04-11
One Click Demo Import HIGH 7.2
CVE-2022-1008

The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload ar…

Fix: 3.1.0+
Fix from $1,950 2022-04-11