Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Dswjcms CRITICAL 9.8
CVE-2020-19267

An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

No fix yet
Fix from $2,300 2021-09-09
Showdoc CRITICAL 9.8
CVE-2021-36440

Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdat…

No fix yet
Fix from $2,300 2021-09-08
Dotcms CRITICAL 9.8
CVE-2020-19138EPSS 6%

Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src…

Fix: after 5.2.3
Fix from $2,300 2021-09-08
Simple Water Refilling Station Management System HIGH 8.8
CVE-2021-38841

Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page in classes…

No fix yet
Fix from $1,950 2021-09-07
Sketch CRITICAL 9.8
CVE-2021-40531EPSS 33%

Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quar…

Fix: 75+
Fix from $2,300 2021-09-06
Pure Ftpd HIGH 7.5
CVE-2021-40524

In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lea…

Fix: 1.0.50+
Fix from $1,950 2021-09-05
Adobe Commerce HIGH 7.2
CVE-2021-36040

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Adobe Commerce HIGH 7.2
CVE-2021-36042

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Openpages With Watson HIGH 8.8
CVE-2021-29907

IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force…

Fix: 8.1.0.2.1 / 8.2.0.2+
Fix from $1,950 2021-08-31
Viaware CRITICAL 9.8
CVE-2021-36356EPSS 54%

KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary …

Fix: after 2021-08
Fix from $2,300 2021-08-31
Diaenergie CRITICAL 9.8
CVE-2021-32955EPSS 37%

Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

Fix: after 1.7.5
Fix from $2,300 2021-08-30
Manageengine Log360 CRITICAL 9.8
CVE-2021-40175EPSS 7%

Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.

Fix: after 5.1
Fix from $2,300 2021-08-29
Dedecms CRITICAL 9.8
CVE-2020-18114

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.

No fix yet
Fix from $2,300 2021-08-27
Spacecom2 CRITICAL 9.1
CVE-2021-33884

An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any file…

Fix: 012u000062+
Fix from $2,300 2021-08-25
Remkon Device Manager CRITICAL 9.8
CVE-2021-38613

The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and a…

No fix yet
Fix from $2,300 2021-08-24
Flatcore Cms HIGH 7.2
CVE-2021-39608EPSS 46%

Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arb…

No fix yet
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39153

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39154

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39141EPSS 16%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.5
CVE-2021-39145

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39146EPSS 14%

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39147

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39148

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39149

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Fedora HIGH 8.5
CVE-2021-39151

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Debian Linux HIGH 8.8
CVE-2021-39139

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a…

Fix: 1.4.18+
Fix from $1,950 2021-08-23
Seopanel HIGH 8.8
CVE-2020-27461

A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an aut…

Patch available
Fix from $1,950 2021-08-20
Bludit CRITICAL 9.8
CVE-2020-18879

Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln…

No fix yet
Fix from $2,300 2021-08-20
Phpmywind HIGH 7.2
CVE-2020-18886

Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

No fix yet
Fix from $1,950 2021-08-20
Ofbiz CRITICAL 9.8
CVE-2021-37608EPSS 6%

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach…

Fix: 17.12.08+
Fix from $2,300 2021-08-18