Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Security Verify Access MEDIUM 6.8
CVE-2021-29699

IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excute…

Patch available
Fix from $1,600 2021-07-15
Sharecare HIGH 8.8
CVE-2021-36121

An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestri…

Mitigation only
Fix from $1,950 2021-07-13
Vsa CRITICAL 9.8
CVE-2021-30118EPSS 60%

An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and …

Fix: 9.5.5+
Fix from $2,300 2021-07-09
Fork Cms HIGH 8.8
CVE-2021-28931

Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zi…

Mitigation only
Fix from $1,950 2021-07-07
Artware Cms CRITICAL 9.8
CVE-2021-32538

ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files with…

Fix: 2021-01-08+
Fix from $2,300 2021-07-07
Profilepress CRITICAL 9.8
CVE-2021-34623

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possib…

Fix: after 3.1.3
Fix from $2,300 2021-07-07
Profilepress CRITICAL 9.8
CVE-2021-34624EPSS 7%

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible…

Fix: after 3.1.3
Fix from $2,300 2021-07-07
Phplist CRITICAL 9.8
CVE-2020-22249

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a m…

No fix yet
Fix from $2,300 2021-07-06
Machform HIGH 8.1
CVE-2021-20104

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded wit…

Fix: 16+
Fix from $1,950 2021-06-29
Business Intelligence And Reporting Tools CRITICAL 9.8
CVE-2021-34427EPSS 58%

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT v…

Fix: after 4.8.0
Fix from $2,300 2021-06-25
Pandora Fms CRITICAL 9.8
CVE-2021-34074EPSS 7%

PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a rel…

Fix: after 754
Fix from $2,300 2021-06-25
Ibos CRITICAL 9.8
CVE-2020-21786

In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.

No fix yet
Fix from $2,300 2021-06-24
Crmeb CRITICAL 9.8
CVE-2020-21787

CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

No fix yet
Fix from $2,300 2021-06-24
Getsimplecms HIGH 7.2
CVE-2021-28976EPSS 8%

Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.

Fix: 3.3.15+
Fix from $1,950 2021-06-23
Joomla\! CRITICAL 9.8
CVE-2010-1433

Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…

Fix: after 1.5.15
Fix from $2,300 2021-06-21
Autoptimize CRITICAL 9.8
CVE-2021-24376

The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" f…

Fix: 2.7.8+
Fix from $2,300 2021-06-21
Fancy Product Designer CRITICAL 9.8
CVE-2021-24370EPSS 47%

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code executi…

Fix: 4.6.9+
Fix from $2,300 2021-06-21
Textpattern CRITICAL 9.8
CVE-2020-19510

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

No fix yet
Fix from $2,300 2021-06-21
Civicrm HIGH 8.8
CVE-2020-36388

In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.

Fix: 5.21.3 / 5.24.3+
Fix from $1,950 2021-06-17
Framework CRITICAL 9.8
CVE-2013-20002

Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/the…

Fix: 1.2.2+
Fix from $2,300 2021-06-17
Fogproject HIGH 8.8
CVE-2021-32243

FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).

No fix yet
Fix from $1,950 2021-06-16
Fedora HIGH 8.1
CVE-2021-34551

PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.

Fix: 6.5.0+
Fix from $1,950 2021-06-16
Bloofoxcms CRITICAL 9.8
CVE-2020-35760

bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).

No fix yet
Fix from $2,300 2021-06-16
Defibrillator Dashboard HIGH 8.8
CVE-2021-27489

ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow …

Fix: 2.2+
Fix from $1,950 2021-06-16
Laiketui HIGH 8.8
CVE-2021-34128

LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive co…

No fix yet
Fix from $1,950 2021-06-15
Dext5 Editor CRITICAL 9.8
CVE-2020-7864

Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz D…

Fix: 3.5.1405747.1100.03+
Fix from $2,300 2021-06-15
Elfinder CRITICAL 9.8
CVE-2021-23394EPSS 19%

The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only…

Fix: 2.1.58+
Fix from $2,300 2021-06-13
Scadabr HIGH 8.8
CVE-2021-26828 KEVEPSS 39%

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via …

Fix: after 1.12.4
Fix from $1,950 2021-06-11
Bdr Suite CRITICAL 9.8
CVE-2021-26473

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to wri…

Fix: 4.2.0.1+
Fix from $2,300 2021-06-08
Nagios Xi HIGH 7.2
CVE-2021-3277EPSS 55%

Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-in…

Fix: after 5.7.5
Fix from $1,950 2021-06-07