Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Wpanel Cms HIGH 8.8
CVE-2021-34257

Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar imag…

Fix: after 4.3.1
Fix from $1,950 2022-03-31
Hospital Management System CRITICAL 9.8
CVE-2022-24136

Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an atta…

No fix yet
Fix from $2,300 2022-03-31
Banking System CRITICAL 9.8
CVE-2022-26645

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file u…

Mitigation only
Fix from $2,300 2022-03-30
Kio Firmware HIGH 7.2
CVE-2022-28223

Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.

Fix: after 2022-03-30
Fix from $1,950 2022-03-30
Student Attendance Management System CRITICAL 9.8
CVE-2021-45865

A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.

No fix yet
Fix from $2,300 2022-03-29
Bbs HIGH 7.2
CVE-2021-43098

A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.

No fix yet
Fix from $1,950 2022-03-28
Bbs HIGH 7.2
CVE-2021-43100

A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitra…

No fix yet
Fix from $1,950 2022-03-28
Bbs HIGH 7.2
CVE-2021-43101

A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execut…

No fix yet
Fix from $1,950 2022-03-28
Bbs HIGH 7.2
CVE-2021-43102

A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrar…

No fix yet
Fix from $1,950 2022-03-28
Bbs HIGH 7.2
CVE-2021-43103

A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitra…

No fix yet
Fix from $1,950 2022-03-28
Sermon Browser HIGH 8.8
CVE-2022-0499

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any…

Fix: after 0.45.22
Fix from $1,950 2022-03-28
Checkmk HIGH 8.8
CVE-2021-40905

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which …

Fix: 2.0.0+
Fix from $1,950 2022-03-25
Taocms CRITICAL 9.8
CVE-2022-23880

An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a craft…

No fix yet
Fix from $2,300 2022-03-23
Ninja Forms File Uploads CRITICAL 9.8
CVE-2022-0888EPSS 39%

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation foun…

Fix: after 3.3.0
Fix from $2,300 2022-03-23
Carbon Black App Control CRITICAL 9.1
CVE-2022-22952

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload v…

Fix: 8.5.14 / 8.6.6+
Fix from $2,300 2022-03-23
Multilin B30 Firmware CRITICAL 9.8
CVE-2021-27428

GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup t…

Fix: 8.10+
Fix from $2,300 2022-03-23
Crater HIGH 7.8
CVE-2022-1033

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

Fix: 6.0.6+
Fix from $1,950 2022-03-23
Showdoc HIGH 7.2
CVE-2022-1034

There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

Fix: 2.10.4+
Fix from $1,950 2022-03-22
Bigant Server HIGH 8.8
CVE-2022-23346

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

Mitigation only
Fix from $1,950 2022-03-21
Amelia HIGH 8.8
CVE-2022-0687

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backd…

Fix: 1.0.47+
Fix from $1,950 2022-03-21
Gogs HIGH 8.8
CVE-2022-0415EPSS 65%

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

Fix: 0.12.6+
Fix from $1,950 2022-03-21
Shopxo HIGH 7.8
CVE-2020-26007

An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a craft…

No fix yet
Fix from $1,950 2022-03-20
Shopxo HIGH 7.8
CVE-2020-26008

The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allo…

No fix yet
Fix from $1,950 2022-03-20
Dwsurvey CRITICAL 9.8
CVE-2021-39384

DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java.

No fix yet
Fix from $2,300 2022-03-20
Classcms HIGH 7.8
CVE-2022-25581

Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code i…

Fix: after 2.5
Fix from $1,950 2022-03-18
Responsive Menu HIGH 8.8
CVE-2022-25602

Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugi…

Fix: after 4.1.7
Fix from $1,950 2022-03-18
Opendocman CRITICAL 9.8
CVE-2021-45834

An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically …

Mitigation only
Fix from $2,300 2022-03-18
Online Admissions System CRITICAL 9.8
CVE-2021-45835

The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through document…

No fix yet
Fix from $2,300 2022-03-18
Pluck HIGH 7.2
CVE-2022-26965EPSS 36%

In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.

No fix yet
Fix from $1,950 2022-03-18
Laravel Media Library CRITICAL 9.8
CVE-2021-45040

The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the upl…

Fix: after 2.1.6
Fix from $2,300 2022-03-17