Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Jeecg CRITICAL 9.8
CVE-2020-23083

Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file t…

Fix: after 4.0
Fix from $2,300 2021-05-03
Isc2500 S Firmware CRITICAL 9.8
CVE-2020-21452

An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC…

Mitigation only
Fix from $2,300 2021-04-29
Business Hours Pro CRITICAL 9.8
CVE-2021-24240

The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leadi…

Fix: after 5.5.0
Fix from $2,300 2021-04-22
Textpattern MEDIUM 6.5
CVE-2021-30209

Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification,…

No fix yet
Fix from $1,600 2021-04-15
Orchard CRITICAL 9.8
CVE-2020-29592

An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload al…

Fix: 1.10+
Fix from $2,300 2021-04-14
Intelligent Power Manager CRITICAL 9.9
CVE-2021-23280

Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an a…

Fix: 1.68 / 1.69+
Fix from $2,300 2021-04-13
Focusblog CRITICAL 9.1
CVE-2021-24220

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPr…

Fix: 2.0.0+
Fix from $2,300 2021-04-12
Wp Curriculo Vitae Free CRITICAL 9.8
CVE-2021-24222

The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The f…

Fix: after 6.3
Fix from $2,300 2021-04-12
N5 Upload Form CRITICAL 9.8
CVE-2021-24223

The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any fil…

Fix: after 1.0
Fix from $2,300 2021-04-12
Easy Form Builder By Bitware HIGH 8.8
CVE-2021-24224

The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any se…

Fix: after 1.0
Fix from $1,950 2021-04-12
Email Security HIGH 7.2
CVE-2021-20022 KEVEPSS 17%

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remot…

Fix: 10.0.9.6103 / 10.0.9.6105+
Fix from $1,950 2021-04-09
Directus HIGH 8.8
CVE-2021-29641

Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .…

Fix: 8.8.2+
Fix from $1,950 2021-04-07
Deltaflow CRITICAL 9.8
CVE-2021-28173

The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitra…

Fix: 7.7+
Fix from $2,300 2021-04-06
Composr CRITICAL 9.8
CVE-2021-30149EPSS 10%

Composr 10.0.36 allows upload and execution of PHP files.

Patch available
Fix from $2,300 2021-04-06
Help Scout CRITICAL 9.8
CVE-2021-24212EPSS 8%

The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to u…

Fix: 2.9.1+
Fix from $2,300 2021-04-05
Responsive Menu HIGH 8.8
CVE-2021-24160EPSS 8%

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would …

Fix: 4.0.4+
Fix from $1,950 2021-04-05
Woocommerce Upload Files CRITICAL 9.8
CVE-2021-24171

The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible t…

Fix: 59.4+
Fix from $2,300 2021-04-05
Backup Guard HIGH 7.2
CVE-2021-24155EPSS 84%

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format an…

Fix: 1.6.0+
Fix from $1,950 2021-04-05
Emlog CRITICAL 9.8
CVE-2020-21585

Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.

No fix yet
Fix from $2,300 2021-04-02
Simple College HIGH 7.2
CVE-2020-28173

Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious …

No fix yet
Fix from $1,950 2021-03-31
Wifi Mini Spy 1080p Hd Security Ip Camera Firmware MEDIUM 6.2
CVE-2020-19642

An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recd…

No fix yet
Fix from $1,600 2021-03-30
Prosafe Network Management System CRITICAL 9.8
CVE-2021-27274EPSS 8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.…

Mitigation only
Fix from $2,300 2021-03-29
Netact MEDIUM 6.5
CVE-2021-26597

An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web sit…

No fix yet
Fix from $1,600 2021-03-25
TYPO3 HIGH 8.6
CVE-2021-21355

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensurin…

Fix: 8.7.40 / 9.5.25+
Fix from $1,950 2021-03-23
TYPO3 HIGH 8.3
CVE-2021-21357

TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input valid…

Fix: 8.7.40 / 9.5.25+
Fix from $1,950 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21347EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21350EPSS 15%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.1
CVE-2021-21351EPSS 82%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21344EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23
Activemq CRITICAL 9.8
CVE-2021-21346EPSS 76%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $2,300 2021-03-23