Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Connect Secure HIGH 7.2
CVE-2021-22937EPSS 8%

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted ar…

Fix: 9.1+
Fix from $1,950 2021-08-16
Widgy CRITICAL 9.8
CVE-2020-18704

Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in th…

No fix yet
Fix from $2,300 2021-08-16
Simple Image Gallery Web App CRITICAL 9.8
CVE-2021-38753

An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the se…

No fix yet
Fix from $2,300 2021-08-16
Pearadmin Think CRITICAL 9.8
CVE-2021-29377

Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can b…

Fix: after 2.1.2
Fix from $2,300 2021-08-12
Sitecore HIGH 8.8
CVE-2021-38366

Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution b…

Fix: after 10.1
Fix from $1,950 2021-08-12
Aikcms HIGH 7.2
CVE-2020-18462

File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file.

No fix yet
Fix from $1,950 2021-08-12
Ljcms CRITICAL 9.8
CVE-2020-20979

An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2021-08-12
Zentao CRITICAL 9.8
CVE-2020-28165

The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the serv…

Fix: 12.4.2+
Fix from $2,300 2021-08-12
Maccms CRITICAL 9.8
CVE-2020-21359

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execu…

No fix yet
Fix from $2,300 2021-08-11
Newsone Cms HIGH 8.8
CVE-2020-21976

An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitr…

No fix yet
Fix from $1,950 2021-08-11
Yamale HIGH 7.8
CVE-2021-38305

23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its p…

Fix: 3.0.8+
Fix from $1,950 2021-08-09
Workreap CRITICAL 9.8
CVE-2021-24499EPSS 60%

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks…

Fix: 2.2.2+
Fix from $2,300 2021-08-09
Jeecg Boot CRITICAL 9.8
CVE-2020-28088

An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2021-08-06
Download Manager HIGH 8.8
CVE-2021-34639

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. …

Fix: after 3.1.24
Fix from $1,950 2021-08-05
Fortiportal HIGH 8.1
CVE-2021-32594

An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.…

Fix: 5.2.6 / 5.3.6+
Fix from $1,950 2021-08-04
Hdcms HIGH 7.8
CVE-2020-19303

An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $1,950 2021-08-03
Vaethink CRITICAL 9.8
CVE-2020-19302

An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded fil…

No fix yet
Fix from $2,300 2021-08-03
Online Covid Vaccination Scheduler System CRITICAL 9.8
CVE-2021-36622

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function …

No fix yet
Fix from $2,300 2021-08-03
Phone Shop Sales Management System CRITICAL 9.8
CVE-2021-36623

Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.

No fix yet
Fix from $2,300 2021-08-03
Learning Management System CRITICAL 9.8
CVE-2021-25200

Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file uploa…

No fix yet
Fix from $2,300 2021-07-30
Officescan HIGH 8.8
CVE-2021-36741 KEV

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 a…

Mitigation only
Fix from $1,950 2021-07-29
Ivm Attendant HIGH 8.8
CVE-2021-37444

NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execut…

Fix: after 5.12
Fix from $1,950 2021-07-25
Victor Cms CRITICAL 9.8
CVE-2021-25203

Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\inclu…

No fix yet
Fix from $2,300 2021-07-23
Responsive Ordering System CRITICAL 9.8
CVE-2021-25206

Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload…

No fix yet
Fix from $2,300 2021-07-23
Travel Management System CRITICAL 9.8
CVE-2021-25208

Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload t…

No fix yet
Fix from $2,300 2021-07-23
E Commerce Website CRITICAL 9.8
CVE-2021-25207

Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prod…

No fix yet
Fix from $2,300 2021-07-23
Online Ordering System CRITICAL 9.8
CVE-2021-25211

Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to orderi…

No fix yet
Fix from $2,300 2021-07-22
Alumni Management System CRITICAL 9.8
CVE-2021-25210

Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload …

Mitigation only
Fix from $2,300 2021-07-22
Stock Manager For Woocommerce HIGH 8.8
CVE-2021-34619

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and in…

Fix: after 2.5.7
Fix from $1,950 2021-07-21
Orca Hcm CRITICAL 9.8
CVE-2021-35963

The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated …

Fix: after 10.0
Fix from $2,300 2021-07-19