Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Pgadmin 4 MEDIUM 6.5
CVE-2022-0959

A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually uploa…

Fix: 6.7+
Fix from $1,600 2022-03-16
Atomcms CRITICAL 9.8
CVE-2022-25487EPSS 54%

Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

No fix yet
Fix from $2,300 2022-03-15
Cuppacms CRITICAL 9.8
CVE-2022-25495

The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a c…

No fix yet
Fix from $2,300 2022-03-15
Showdoc MEDIUM 6.1
CVE-2022-0951

File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.

Fix: after 2.10.3
Fix from $1,600 2022-03-15
Showdoc MEDIUM 5.4
CVE-2022-0950

Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.

Fix: after 2.10.3
Fix from $1,600 2022-03-15
Showdoc MEDIUM 5.4
CVE-2022-0945

Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.

Fix: after 2.10.3
Fix from $1,600 2022-03-15
Sylius MEDIUM 6.1
CVE-2022-24749

Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-…

Fix: 1.9.10 / 1.10.11+
Fix from $1,600 2022-03-14
Showdoc MEDIUM 5.4
CVE-2022-0962

Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.

Fix: 2.10.4+
Fix from $1,600 2022-03-14
Showdoc MEDIUM 5.4
CVE-2022-0960

Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

Fix: 2.10.4+
Fix from $1,600 2022-03-14
Zenario HIGH 7.2
CVE-2021-42171

Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, …

No fix yet
Fix from $1,950 2022-03-14
Wpcargo Track \& Trace CRITICAL 9.8
CVE-2021-25003EPSS 56%

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on t…

Fix: 6.9.0+
Fix from $2,300 2022-03-14
Smartertrack HIGH 7.2
CVE-2022-24387

With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml f…

Fix: 100.0.8075+
Fix from $1,950 2022-03-14
Microweber MEDIUM 6.7
CVE-2022-0921

Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

Fix: 1.2.12+
Fix from $1,600 2022-03-11
Croogo HIGH 8.8
CVE-2021-44673EPSS 9%

A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell …

No fix yet
Fix from $1,950 2022-03-10
Abantecart HIGH 7.2
CVE-2022-26521EPSS 10%

Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Me…

Fix: after 1.3.2
Fix from $1,950 2022-03-10
Sentcms CRITICAL 9.8
CVE-2022-24652

sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution …

No fix yet
Fix from $2,300 2022-03-10
Sentcms CRITICAL 9.8
CVE-2022-24651

sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution …

No fix yet
Fix from $2,300 2022-03-10
Quicklert HIGH 8.8
CVE-2021-43970

An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begin…

No fix yet
Fix from $1,950 2022-03-10
Catch Themes Demo Import HIGH 7.2
CVE-2022-0440

The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin…

Fix: 2.1.1+
Fix from $1,950 2022-03-07
Wordpress File Upload MEDIUM 5.4
CVE-2021-24960

The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as…

Fix: 4.16.3+
Fix from $1,600 2022-03-07
One Stop Wp Migration HIGH 7.2
CVE-2021-24216

The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files…

Fix: 7.41+
Fix from $1,950 2022-03-07
Home Owners Collection Management System HIGH 7.8
CVE-2022-25115

A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v…

No fix yet
Fix from $1,950 2022-03-02
Home Owners Collection Management System CRITICAL 9.8
CVE-2022-25016

Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/…

No fix yet
Fix from $2,300 2022-03-02
Portfolio HIGH 8.8
CVE-2022-24251

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

Mitigation only
Fix from $1,950 2022-03-01
Portfolio HIGH 8.8
CVE-2022-24252

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2022-03-01
Portfolio HIGH 8.8
CVE-2022-24253

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

Mitigation only
Fix from $1,950 2022-03-01
Portfolio HIGH 8.8
CVE-2022-24254

An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2022-03-01
Cms Made Simple HIGH 7.2
CVE-2022-23906

CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability i…

No fix yet
Fix from $1,950 2022-02-28
Maxsite Cms CRITICAL 9.8
CVE-2022-25411

A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $2,300 2022-02-28
Revolution HIGH 7.2
CVE-2022-26149EPSS 9%

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Up…

Fix: after 2.8.3
Fix from $1,950 2022-02-26