Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Jpress HIGH 8.8
CVE-2021-45808

jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.

Mitigation only
Fix from $1,950 2022-01-19
Free School Management Software CRITICAL 9.8
CVE-2021-46013

An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability t…

No fix yet
Fix from $2,300 2022-01-18
Pimcore HIGH 7.8
CVE-2022-0263

Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

Fix: 10.2.7+
Fix from $1,950 2022-01-18
Saraban CRITICAL 9.8
CVE-2021-38697

SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which …

No fix yet
Fix from $2,300 2022-01-18
Connection Broker HIGH 7.2
CVE-2021-41550

Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.

Mitigation only
Fix from $1,950 2022-01-18
Crater HIGH 7.2
CVE-2022-0242

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.

Fix: 6.0+
Fix from $1,950 2022-01-17
Files Antivirus HIGH 8.8
CVE-2021-33828

The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a pu…

Fix: 1.0.0+
Fix from $1,950 2022-01-15
Commcell HIGH 8.8
CVE-2021-34995EPSS 69%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…

Mitigation only
Fix from $1,950 2022-01-13
Commcell HIGH 8.8
CVE-2021-34997

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…

Mitigation only
Fix from $1,950 2022-01-13
Printable Staff Id Card Creator System CRITICAL 9.8
CVE-2021-45411

In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbit…

No fix yet
Fix from $2,300 2022-01-12
Manageengine Cloud Security Plus HIGH 8.8
CVE-2021-44651EPSS 5%

Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper…

Fix: 4.1+
Fix from $1,950 2022-01-12
Crater HIGH 8.8
CVE-2021-4080

crater is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 6.0.0+
Fix from $1,950 2022-01-12
Sysaid HIGH 8.8
CVE-2021-43973

An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitra…

Patch available
Fix from $1,950 2022-01-11
Vehicle Service Management System HIGH 7.2
CVE-2021-46079

An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious file…

Fix: after 1.0
Fix from $1,950 2022-01-06
Vehicle Service Management System HIGH 8.8
CVE-2021-46076

Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints …

No fix yet
Fix from $1,950 2022-01-06
Kace Desktop Authority CRITICAL 9.8
CVE-2021-44031

An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a…

Fix: 11.2+
Fix from $2,300 2021-12-22
Directorist HIGH 7.5
CVE-2021-24981

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell upl…

Fix: 7.0.6.2+
Fix from $1,950 2021-12-21
Orion Platform HIGH 7.2
CVE-2021-35244EPSS 6%

The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An…

Fix: 2020.2.6+
Fix from $1,950 2021-12-20
Gcb Doctor CRITICAL 9.8
CVE-2021-44159

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files w…

Fix: 2021-09-16+
Fix from $2,300 2021-12-20
Qb Smart Service Robot CRITICAL 9.8
CVE-2021-44164

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pa…

Mitigation only
Fix from $2,300 2021-12-20
Laravel Filemanager HIGH 8.8
CVE-2021-23814

This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type wh…

Mitigation only
Fix from $1,950 2021-12-17
Opencats CRITICAL 9.8
CVE-2021-41560EPSS 11%

OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.

Fix: after 0.9.6
Fix from $2,300 2021-12-15
Remote View Pro Firmware HIGH 8.8
CVE-2021-41870

An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type…

Mitigation only
Fix from $1,950 2021-12-15
Patrowlmanager HIGH 8.8
CVE-2021-43829EPSS 59%

PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle uploa…

Fix: 1.7.7+
Fix from $1,950 2021-12-14
Emlog CRITICAL 9.8
CVE-2021-40883

A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.

No fix yet
Fix from $2,300 2021-12-14
Fastadmin CRITICAL 9.8
CVE-2021-43117

fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.

No fix yet
Fix from $2,300 2021-12-13
Pluck HIGH 8.1
CVE-2021-27984

In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

No fix yet
Fix from $1,950 2021-12-10
Mail Secure HIGH 8.8
CVE-2021-36719

PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to up…

Fix: 5.2.1+
Fix from $1,950 2021-12-08
Ipvpn Firmware HIGH 8.8
CVE-2021-27860 KEVEPSS 40%

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a re…

Mitigation only
Fix from $1,950 2021-12-08
Avalanche HIGH 8.8
CVE-2021-42125EPSS 82%

An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dan…

Fix: 6.3.3+
Fix from $1,950 2021-12-07