Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Monstra CRITICAL 9.8
CVE-2021-36548

A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows a…

No fix yet
Fix from $2,300 2021-10-28
Flatcore Cms MEDIUM 6.6
CVE-2021-3745

flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 2.1.0+
Fix from $1,600 2021-10-28
Bookstack MEDIUM 6.5
CVE-2021-3906

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 21.10.1+
Fix from $1,600 2021-10-27
Customer Relationship Management System HIGH 8.8
CVE-2021-37221

A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create opti…

No fix yet
Fix from $1,950 2021-10-27
Online Student Admission System HIGH 8.8
CVE-2021-37372

Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by upd…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi HIGH 7.2
CVE-2021-40344EPSS 66%

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary exten…

No fix yet
Fix from $1,950 2021-10-26
Server MEDIUM 6.5
CVE-2021-41178

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes a…

Fix: 20.0.13 / 21.0.5+
Fix from $1,600 2021-10-25
Contacts MEDIUM 5.4
CVE-2021-39221

Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored …

Fix: 4.0.3+
Fix from $1,600 2021-10-25
Playable HIGH 7.8
CVE-2020-36485

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vul…

No fix yet
Fix from $1,950 2021-10-22
Air Sender HIGH 8.8
CVE-2020-23043

Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers …

No fix yet
Fix from $1,950 2021-10-22
Suitecrm HIGH 8.8
CVE-2021-42840EPSS 59%

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account …

Fix: 7.11.19+
Fix from $1,950 2021-10-22
Showdoc CRITICAL 9.8
CVE-2021-41745

ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

Mitigation only
Fix from $2,300 2021-10-22
Versiondog CRITICAL 9.1
CVE-2021-38471

There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.

Fix: 8.0.0+
Fix from $2,300 2021-10-22
Catch Themes Demo Import HIGH 7.2
CVE-2021-39352EPSS 56%

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemo…

Fix: after 1.7
Fix from $1,950 2021-10-21
Firefly Iii HIGH 8.8
CVE-2021-3846

firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 5.6.2+
Fix from $1,950 2021-10-19
Ir615 Firmware HIGH 7.2
CVE-2021-38484

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicio…

Mitigation only
Fix from $1,950 2021-10-19
Brizy Page Builder HIGH 8.8
CVE-2021-38346

The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the …

Fix: after 2.3.11
Fix from $1,950 2021-10-14
Goahead CRITICAL 9.8
CVE-2021-42342EPSS 59%

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without bein…

Fix: 5.1.5+
Fix from $2,300 2021-10-14
Manageengine Admanager Plus HIGH 8.8
CVE-2021-20130EPSS 33%

ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in…

Fix: 7.1+
Fix from $1,950 2021-10-13
Manageengine Admanager Plus HIGH 8.8
CVE-2021-20131EPSS 17%

ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in…

Fix: 7.1+
Fix from $1,950 2021-10-13
Vigorconnect CRITICAL 9.8
CVE-2021-20125

An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect…

No fix yet
Fix from $2,300 2021-10-13
Phpfusion HIGH 7.2
CVE-2021-40188

PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions…

No fix yet
Fix from $1,950 2021-10-11
Phpfusion HIGH 7.2
CVE-2021-40189

PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], wh…

No fix yet
Fix from $1,950 2021-10-11
Access Demo Importer HIGH 8.8
CVE-2021-39317

A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_insta…

Fix: 1.0.7+
Fix from $1,950 2021-10-11
Webtareas HIGH 8.8
CVE-2021-41919

webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is workin…

Fix: after 2.4
Fix from $1,950 2021-10-08
Tadtools CRITICAL 9.8
CVE-2021-41566

The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary co…

Fix: 3.2.2+
Fix from $2,300 2021-10-08
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37762EPSS 8%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37918EPSS 74%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37919EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37920EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07