Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Bloofoxcms HIGH 8.8
CVE-2020-36141

BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' …

No fix yet
Fix from $1,950 2021-06-04
\@backstage\/plugin Techdocs HIGH 7.3
CVE-2021-32661

Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.…

Fix: 0.9.5+
Fix from $1,950 2021-06-03
\@backstage\/techdocs Common HIGH 8.1
CVE-2021-32660

Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versio…

Fix: 0.6.4+
Fix from $1,950 2021-06-03
Wellcms MEDIUM 6.5
CVE-2020-21005

WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is control…

No fix yet
Fix from $1,600 2021-06-03
Fdcms CRITICAL 9.8
CVE-2020-35442

FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background via Front/lib/Action/FindexAct…

No fix yet
Fix from $2,300 2021-06-02
Photo Station HIGH 8.8
CVE-2021-29092

Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote…

Fix: 6.8.14-3500+
Fix from $1,950 2021-06-01
External Media HIGH 8.8
CVE-2021-24311

The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any auth…

Fix: 1.0.34+
Fix from $1,950 2021-06-01
Ichris CRITICAL 9.8
CVE-2021-31703

Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.

Fix: after 5.18
Fix from $2,300 2021-05-29
Vfairs HIGH 8.8
CVE-2020-26678

vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a p…

Mitigation only
Fix from $1,950 2021-05-26
Bludit HIGH 7.2
CVE-2020-23765

A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Ad…

No fix yet
Fix from $1,950 2021-05-21
Admidio HIGH 8.8
CVE-2021-32630

Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenti…

Fix: 4.0.4+
Fix from $1,950 2021-05-20
X Stream Enhanced Xegp Firmware CRITICAL 9.8
CVE-2021-27459

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvali…

Mitigation only
Fix from $2,300 2021-05-20
Konawiki CRITICAL 9.8
CVE-2021-20721

KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbit…

Fix: 2.2.4+
Fix from $2,300 2021-05-20
Matrix React Sdk HIGH 7.8
CVE-2021-32622

Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the loca…

Fix: 3.21.0+
Fix from $1,950 2021-05-17
Laobancms CRITICAL 9.8
CVE-2020-18166

Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the c…

No fix yet
Fix from $2,300 2021-05-14
Kaswara CRITICAL 9.8
CVE-2021-24284EPSS 42%

The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The su…

Fix: after 3.0.1
Fix from $2,300 2021-05-14
Articlecms CRITICAL 9.8
CVE-2020-20092

File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP …

No fix yet
Fix from $2,300 2021-05-13
Articlecms CRITICAL 9.8
CVE-2020-28063

A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.

No fix yet
Fix from $2,300 2021-05-13
Golo CRITICAL 9.8
CVE-2020-23790

An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.

No fix yet
Fix from $2,300 2021-05-12
Fx9500 Firmware CRITICAL 9.8
CVE-2021-32089

An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary fil…

Mitigation only
Fix from $2,300 2021-05-11
Exchange Server MEDIUM 6.6
CVE-2021-31207 KEVEPSS 100%

Microsoft Exchange Server Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2021-05-11
Invoiceplane MEDIUM 5.3
CVE-2021-29022

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

No fix yet
Fix from $1,600 2021-05-10
Emissary HIGH 8.8
CVE-2021-32094

U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files.

Mitigation only
Fix from $1,950 2021-05-07
Emlog CRITICAL 9.8
CVE-2021-31737

emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.

No fix yet
Fix from $2,300 2021-05-06
Imagements CRITICAL 9.8
CVE-2021-24236EPSS 7%

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to fo…

Fix: after 1.2.5
Fix from $2,300 2021-05-06
Business Directory Plugin Easy Listing Directories HIGH 7.2
CVE-2021-24248

The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forb…

Fix: 5.11.1+
Fix from $1,950 2021-05-06
Event Banner HIGH 7.2
CVE-2021-24252

The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .ex…

Fix: after 1.3
Fix from $1,950 2021-05-06
Classyfrieds HIGH 8.8
CVE-2021-24253

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the …

Fix: after 3.8
Fix from $1,950 2021-05-06
College Publisher Import HIGH 7.2
CVE-2021-24254

The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload…

Fix: after 0.1
Fix from $1,950 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19113

Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.

No fix yet
Fix from $2,300 2021-05-06