Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Xerte HIGH 8.8
CVE-2021-44664EPSS 13%

An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a malici…

Fix: after 3.9
Fix from $1,950 2022-02-24
Fireware HIGH 8.8
CVE-2022-25360

WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. Th…

Fix: 12.1.3 / 12.5.9+
Fix from $1,950 2022-02-24
Zenario HIGH 7.2
CVE-2022-23043

Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extens…

Patch available
Fix from $1,950 2022-02-24
Limesurvey HIGH 8.8
CVE-2021-44967EPSS 14%

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious…

No fix yet
Fix from $1,950 2022-02-24
Zfaka CRITICAL 9.8
CVE-2022-24553

An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execut…

Fix: after 1.4.5
Fix from $2,300 2022-02-21
Wikidocs HIGH 8.8
CVE-2022-23375EPSS 20%

WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form…

No fix yet
Fix from $1,950 2022-02-19
Showdoc HIGH 7.8
CVE-2022-0409

Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.

Fix: 2.10.2+
Fix from $1,950 2022-02-19
Mcms CRITICAL 9.8
CVE-2021-46036

An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2022-02-18
Jqueryform CRITICAL 9.8
CVE-2022-24984

Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executabl…

Fix: 2022-02-05+
Fix from $2,300 2022-02-16
Bbs Forum CRITICAL 9.8
CVE-2022-23390

An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.

Fix: after 5.3
Fix from $2,300 2022-02-14
Interactive Graphical Scada System Data Collector CRITICAL 9.8
CVE-2021-22803

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, w…

Fix: after 15.0.0.21243
Fix from $2,300 2022-02-11
Drupal CRITICAL 9.8
CVE-2020-13675

Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which cause…

Fix: 8.9.19 / 9.1.13+
Fix from $2,300 2022-02-11
Exponent Cms HIGH 7.2
CVE-2022-23048

Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. Af…

No fix yet
Fix from $1,950 2022-02-09
Comos HIGH 7.5
CVE-2021-37194

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web …

Fix: 10.3.3.3 / 10.4.1+
Fix from $1,950 2022-02-09
Composr HIGH 8.8
CVE-2021-46360EPSS 9%

Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP sh…

Fix: after 10.0.39
Fix from $1,950 2022-02-09
Hybbs2 HIGH 8.8
CVE-2022-24676

update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.

Fix: 2.3.3+
Fix from $1,950 2022-02-09
Responsive Vector Maps MEDIUM 6.5
CVE-2021-24947

The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in…

Fix: 6.4.2+
Fix from $1,600 2022-02-07
Laracom MEDIUM 5.4
CVE-2022-0472

Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.

Fix: 2.0.9+
Fix from $1,600 2022-02-04
Jspxcms CRITICAL 9.8
CVE-2022-23329EPSS 14%

A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploadin…

No fix yet
Fix from $2,300 2022-02-04
Voipmonitor HIGH 8.8
CVE-2022-24262

The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to exe…

Fix: 24.96+
Fix from $1,950 2022-02-04
Simple Chatbot Application CRITICAL 9.8
CVE-2021-46428

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parame…

No fix yet
Fix from $2,300 2022-01-27
Dolphinphp HIGH 8.8
CVE-2021-46097

Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log

No fix yet
Fix from $1,950 2022-01-27
Jpress HIGH 7.2
CVE-2021-46115

jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attacke…

No fix yet
Fix from $1,950 2022-01-26
Jpress HIGH 7.2
CVE-2021-46116

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function throug…

No fix yet
Fix from $1,950 2022-01-26
Mcms CRITICAL 9.8
CVE-2021-46386

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingso…

Fix: after 5.2.5
Fix from $2,300 2022-01-26
Spip HIGH 8.8
CVE-2021-44123

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a d…

Patch available
Fix from $1,950 2022-01-26
Forestblog CRITICAL 9.8
CVE-2021-46033

In ForestBlog, as of 2021-12-28, File upload can bypass verification.

No fix yet
Fix from $2,300 2022-01-25
Kea Hotel Erp HIGH 8.8
CVE-2021-46113

In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the…

No fix yet
Fix from $1,950 2022-01-25
Mcms CRITICAL 9.8
CVE-2022-23315

MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

No fix yet
Fix from $2,300 2022-01-21
Mcms CRITICAL 9.8
CVE-2022-22929

MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary cod…

No fix yet
Fix from $2,300 2022-01-21