Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37921EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37923EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37924EPSS 11%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37926EPSS 74%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37928EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37929EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37930EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37931EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-10-07
Integria Ims CRITICAL 9.8
CVE-2021-3832

Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse th…

Mitigation only
Fix from $2,300 2021-10-07
Cobbler HIGH 7.5
CVE-2021-40324EPSS 69%

Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.

Fix: after 3.3.0
Fix from $1,950 2021-10-04
Ecs Router Controller Ecs Firmware CRITICAL 9.8
CVE-2021-41290

ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can r…

Mitigation only
Fix from $2,300 2021-09-30
Fusioncompute HIGH 7.5
CVE-2021-37105

There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be upload…

Mitigation only
Fix from $1,950 2021-09-28
Monstra Cms MEDIUM 6.5
CVE-2020-20691

An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafte…

No fix yet
Fix from $1,600 2021-09-27
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37761EPSS 10%

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

Fix: 7.1+
Fix from $2,300 2021-09-27
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-37539EPSS 93%

Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

Fix: 7.1+
Fix from $2,300 2021-09-27
Frogcms CRITICAL 9.8
CVE-2021-26794

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

No fix yet
Fix from $2,300 2021-09-23
Manageengine Admanager Plus HIGH 8.8
CVE-2021-37741

ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.

Fix: 7.1+
Fix from $1,950 2021-09-21
Simple Schools Staff Directory HIGH 7.2
CVE-2021-24663

The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing h…

Fix: after 1.1
Fix from $1,950 2021-09-20
Jizhicms HIGH 7.2
CVE-2020-21483

An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to …

No fix yet
Fix from $1,950 2021-09-15
Feehicms CRITICAL 9.8
CVE-2020-21322

An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.

Fix: after 2.0.8
Fix from $2,300 2021-09-15
Rgcms HIGH 7.2
CVE-2020-21481

An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a …

No fix yet
Fix from $1,950 2021-09-15
Business One HIGH 8.8
CVE-2021-33698

SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file…

Patch available
Fix from $1,950 2021-09-15
Alphacom Xe Audio Server HIGH 8.8
CVE-2021-40845

The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section a…

Fix: after 11.2.3.10
Fix from $1,950 2021-09-15
Kooboo Cms CRITICAL 9.8
CVE-2021-36581

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the e…

Mitigation only
Fix from $2,300 2021-09-14
Kooboo Cms CRITICAL 9.8
CVE-2021-36582

In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the v…

Mitigation only
Fix from $2,300 2021-09-14
Kitecms HIGH 7.8
CVE-2020-20672

An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.

No fix yet
Fix from $1,950 2021-09-13
Zkeacms HIGH 8.8
CVE-2020-20670

An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.

No fix yet
Fix from $1,950 2021-09-13
Simple E Commerce Shopping Cart HIGH 8.8
CVE-2021-24620

The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable D…

Fix: after 2.2.5
Fix from $1,950 2021-09-13
Shopp CRITICAL 9.8
CVE-2021-24493

The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have a…

Fix: after 1.4
Fix from $2,300 2021-09-13
Email Artillery MEDIUM 6.8
CVE-2021-24490

The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arb…

Fix: after 4.1
Fix from $1,600 2021-09-13