Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Elfinder CRITICAL 9.8
CVE-2022-27115EPSS 29%

In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

Patch available
Fix from $2,300 2022-04-11
Trudesk MEDIUM 5.4
CVE-2022-1045

Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.

Fix: 1.2.0+
Fix from $1,600 2022-04-11
Newbee Mall CRITICAL 9.8
CVE-2022-27477

Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.

No fix yet
Fix from $2,300 2022-04-10
Zbzcms CRITICAL 9.8
CVE-2022-27129

An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

Mitigation only
Fix from $2,300 2022-04-10
Zbzcms CRITICAL 9.8
CVE-2022-27131

An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

Mitigation only
Fix from $2,300 2022-04-10
Mogu Blog Cms CRITICAL 9.8
CVE-2022-27047

mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.

Mitigation only
Fix from $2,300 2022-04-08
Ritecms HIGH 7.2
CVE-2021-46367EPSS 30%

RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP fil…

Fix: after 3.1.0
Fix from $1,950 2022-04-08
Aerocms HIGH 7.2
CVE-2022-27061

AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability…

No fix yet
Fix from $1,950 2022-04-08
Musical World HIGH 8.8
CVE-2022-27064

Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to exec…

No fix yet
Fix from $1,950 2022-04-08
Ecommerce Website HIGH 8.8
CVE-2022-27346

Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attac…

No fix yet
Fix from $1,950 2022-04-08
Social Codia Sms HIGH 7.2
CVE-2022-27349

Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execu…

No fix yet
Fix from $1,950 2022-04-08
Zoo Management System CRITICAL 9.8
CVE-2022-27351

Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows…

No fix yet
Fix from $2,300 2022-04-08
Simple House Rental System HIGH 8.8
CVE-2022-27352

Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attac…

No fix yet
Fix from $1,950 2022-04-08
Ecommerce Website CRITICAL 9.8
CVE-2022-27357

Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers…

No fix yet
Fix from $2,300 2022-04-08
Bigant Office Messenger 5 HIGH 8.8
CVE-2021-43430

An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan…

No fix yet
Fix from $1,950 2022-04-07
Elfinder CRITICAL 9.8
CVE-2021-43421EPSS 43%

A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload ar…

Fix: after 2.1.59
Fix from $2,300 2022-04-07
Online Project Time Management System HIGH 8.8
CVE-2022-26627

Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrar…

No fix yet
Fix from $1,950 2022-04-07
Eziosuite HIGH 8.8
CVE-2022-26605

eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.

No fix yet
Fix from $1,950 2022-04-06
Baigo Cms HIGH 7.2
CVE-2022-26607

A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a cra…

No fix yet
Fix from $1,950 2022-04-06
Jellycms HIGH 8.8
CVE-2022-26630

Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php.

Fix: after 3.8.1
Fix from $1,950 2022-04-05
Horizontcms CRITICAL 9.8
CVE-2021-28428

File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. …

Patch available
Fix from $2,300 2022-04-05
Halo HIGH 7.5
CVE-2022-26619

Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

No fix yet
Fix from $1,950 2022-04-05
Hisiphp HIGH 7.2
CVE-2020-28062

An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plug…

No fix yet
Fix from $1,950 2022-04-04
Library File Manager HIGH 8.1
CVE-2022-0403

The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security…

Fix: 5.2.3+
Fix from $1,950 2022-04-04
Mappress HIGH 7.2
CVE-2022-0537

The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings …

Fix: 2.73.13+
Fix from $1,950 2022-04-04
Ecommerce Website HIGH 8.8
CVE-2022-27435

An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product …

No fix yet
Fix from $1,950 2022-04-04
Online Car Rental System HIGH 8.8
CVE-2022-28062

Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and exec…

No fix yet
Fix from $1,950 2022-04-04
Reftree HIGH 8.8
CVE-2022-27249

An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using Up…

Fix: 2021.09.17+
Fix from $1,950 2022-04-03
Autosave HIGH 7.5
CVE-2021-32961

A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a reques…

Fix: 4.01 / 6.02.06+
Fix from $1,950 2022-04-01
Wyse Management Suite HIGH 7.2
CVE-2022-23155

Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can e…

Fix: after 3.5.2
Fix from $1,950 2022-04-01