Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Avalanche HIGH 8.1
CVE-2021-42133

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Webhmi Firmware CRITICAL 9.8
CVE-2021-43936EPSS 36%

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the …

Fix: 4.1+
Fix from $2,300 2021-12-06
Plupload HIGH 8.8
CVE-2021-23562

This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a u…

Fix: 2.3.9+
Fix from $1,950 2021-12-03
Z Blogphp HIGH 7.8
CVE-2020-29176

An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.

Mitigation only
Fix from $1,950 2021-12-02
Manageengine M365 Manager Plus CRITICAL 9.8
CVE-2021-42099EPSS 7%

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

Mitigation only
Fix from $2,300 2021-11-30
Topease HIGH 8.8
CVE-2021-42123

Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functi…

Fix: after 7.1.27
Fix from $1,950 2021-11-30
Zrlog CRITICAL 9.8
CVE-2021-44093

A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the…

No fix yet
Fix from $2,300 2021-11-28
Zrlog HIGH 7.8
CVE-2021-44094

ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file

No fix yet
Fix from $1,950 2021-11-28
Concrete Cms HIGH 7.2
CVE-2021-22968

A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versio…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
Wordpress Popular Posts HIGH 8.8
CVE-2021-42362EPSS 80%

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/sr…

Fix: after 5.3.2
Fix from $1,950 2021-11-17
Talk MEDIUM 6.1
CVE-2021-39222

Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) …

Fix: 10.0.7 / 10.1.4+
Fix from $1,600 2021-11-15
Webopac HIGH 8.8
CVE-2021-42839

Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attacke…

Mitigation only
Fix from $1,950 2021-11-15
Framework CRITICAL 9.8
CVE-2021-43617EPSS 20%

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAtt…

Fix: after 8.70.2
Fix from $2,300 2021-11-14
Bookstack MEDIUM 5.7
CVE-2021-3915

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 21.10.3+
Fix from $1,600 2021-11-13
Manageengine Patch Connect Plus CRITICAL 9.8
CVE-2021-41833EPSS 8%

Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.

Fix: 9.0.0+
Fix from $2,300 2021-11-11
Beescms HIGH 8.8
CVE-2020-23572

BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attacker…

No fix yet
Fix from $1,950 2021-11-08
Servicetonic CRITICAL 9.8
CVE-2021-28023

Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by …

Fix: 9.0.035937+
Fix from $2,300 2021-11-08
Vantara Pentaho HIGH 8.8
CVE-2021-31599

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows th…

Fix: after 9.1.0.0
Fix from $1,950 2021-11-08
Vantara Pentaho HIGH 7.2
CVE-2021-34685

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated u…

Fix: after 9.1.0.0
Fix from $1,950 2021-11-08
Engineers Online Portal CRITICAL 9.8
CVE-2021-42669EPSS 23%

A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar throu…

No fix yet
Fix from $2,300 2021-11-05
Ed01 Cms CRITICAL 9.8
CVE-2020-18261

An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.

No fix yet
Fix from $2,300 2021-11-03
Doyocms CRITICAL 9.8
CVE-2021-26740

Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2021-11-01
S Cart HIGH 8.8
CVE-2021-38847

S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Admin panel. This vulnerability …

Fix: after 6.4.1
Fix from $1,950 2021-11-01
Learndash HIGH 7.5
CVE-2018-25019

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment…

Fix: after 2.5.4
Fix from $1,950 2021-11-01
Online Reviewer System CRITICAL 9.8
CVE-2021-41646EPSS 7%

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypass…

No fix yet
Fix from $2,300 2021-10-29
Church Management System CRITICAL 9.8
CVE-2021-41643

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.

No fix yet
Fix from $2,300 2021-10-29
Online Food Ordering System CRITICAL 9.8
CVE-2021-41644

Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses th…

No fix yet
Fix from $2,300 2021-10-29
Budget And Expense Tracker System HIGH 8.8
CVE-2021-41645

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to injec…

No fix yet
Fix from $1,950 2021-10-29
E Negosyo System HIGH 7.2
CVE-2021-41675

A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, …

No fix yet
Fix from $1,950 2021-10-29
Mara Cms CRITICAL 9.8
CVE-2021-36547

A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary comman…

No fix yet
Fix from $2,300 2021-10-28