Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Modern Events Calendar Lite HIGH 7.2
CVE-2021-24145EPSS 88%

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing…

Fix: 5.16.5+
Fix from $1,950 2021-03-18
Powerpress HIGH 7.2
CVE-2021-24123

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones fr…

Fix: 8.3.8+
Fix from $1,950 2021-03-18
Online Ordering System CRITICAL 9.8
CVE-2021-28294

Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code…

No fix yet
Fix from $2,300 2021-03-16
Shopxo CRITICAL 9.8
CVE-2021-27817

A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which…

Mitigation only
Fix from $2,300 2021-03-15
Myvesta HIGH 8.8
CVE-2021-28379EPSS 6%

web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different or…

Fix: after 0.9.8-27
Fix from $1,950 2021-03-15
Gatemanager 8250 Firmware HIGH 7.2
CVE-2020-29032

Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious co…

Fix: 9.4.621054022+
Fix from $1,950 2021-03-05
Sonlogger CRITICAL 9.8
CVE-2021-27964EPSS 48%

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFi…

Fix: 6.4.1+
Fix from $2,300 2021-03-05
Zenphoto HIGH 7.2
CVE-2020-36079

Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the upload…

Fix: after 1.5.7
Fix from $1,950 2021-02-26
Myconnection Server CRITICAL 9.8
CVE-2021-27198EPSS 14%

An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in…

Fix: 11.1a+
Fix from $2,300 2021-02-26
Sv Cpt Mc310 Firmware HIGH 8.8
CVE-2021-20659

SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PH…

Fix: 6.5+
Fix from $1,950 2021-02-24
Nas I Firmware HIGH 8.0
CVE-2020-7847

The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote co…

Fix: 1.4.36+
Fix from $1,950 2021-02-23
Yith Woocommerce Gift Cards CRITICAL 9.8
CVE-2021-3120EPSS 37%

An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achiev…

Fix: 3.3.1+
Fix from $2,300 2021-02-22
Eyesofnetwork HIGH 8.8
CVE-2021-27513EPSS 28%

The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre us…

Patch available
Fix from $1,950 2021-02-22
Baby Care System HIGH 7.2
CVE-2021-25780

An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote at…

No fix yet
Fix from $1,950 2021-02-17
Car Rental Portal CRITICAL 9.8
CVE-2021-26809

PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.

No fix yet
Fix from $2,300 2021-02-17
Changjia Property Management System HIGH 8.8
CVE-2021-22858

Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obt…

Mitigation only
Fix from $1,950 2021-02-17
Spectrum Protect Operations Center HIGH 8.0
CVE-2020-4955

IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter…

Fix: 7.1.13.000 / 8.1.10.200+
Fix from $1,950 2021-02-15
Magento CRITICAL 9.1
CVE-2021-21014

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful e…

Fix: 2.3.6+
Fix from $2,300 2021-02-11
Monitorr CRITICAL 9.8
CVE-2020-28871EPSS 86%

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure fi…

No fix yet
Fix from $2,300 2021-02-10
Chrome MEDIUM 6.5
CVE-2021-21131EPSS 8%

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Bot CRITICAL 9.8
CVE-2021-26918

The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins th…

Fix: after 2021-02-08
Fix from $2,300 2021-02-09
Ucopia Wireless Appliance HIGH 8.2
CVE-2020-25037

UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.

Fix: after 6.0.5
Fix from $1,950 2021-02-02
Fortilogger CRITICAL 9.8
CVE-2021-3378EPSS 98%

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then…

Fix: 5.2.0+
Fix from $2,300 2021-02-01
Yccms CRITICAL 9.8
CVE-2020-20287

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote cod…

No fix yet
Fix from $2,300 2021-02-01
Churchrota HIGH 8.8
CVE-2021-3164

ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and e…

No fix yet
Fix from $1,950 2021-01-26
Ecostruxure Power Build Rapsody HIGH 7.8
CVE-2021-22697

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)…

Fix: after 2.1.13
Fix from $1,950 2021-01-26
Ecostruxure Power Build Rapsody HIGH 7.8
CVE-2021-22698

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)…

Fix: after 2.1.13
Fix from $1,950 2021-01-26
Feehi Cms HIGH 7.2
CVE-2020-22643

Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in…

No fix yet
Fix from $1,950 2021-01-26
Openmaint HIGH 8.8
CVE-2020-24549

openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.

Fix: 1.1-2.4.2+
Fix from $1,950 2021-01-26
Openmage HIGH 7.2
CVE-2020-26285

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remo…

Fix: 19.4.10 / 20.0.5+
Fix from $1,950 2021-01-21