Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Openmage HIGH 7.2
CVE-2020-26295

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/…

Fix: 19.4.10 / 20.0.5+
Fix from $1,950 2021-01-21
Openmage HIGH 7.2
CVE-2020-26252

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remo…

Fix: 19.4.10 / 20.0.6+
Fix from $1,950 2021-01-20
Openemr HIGH 8.8
CVE-2020-19364EPSS 71%

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

No fix yet
Fix from $1,950 2021-01-20
Confluence Data Center MEDIUM 6.5
CVE-2020-29450

Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Serv…

Fix: 7.2.0+
Fix from $1,600 2021-01-19
Dsl N14u B1 Firmware HIGH 7.5
CVE-2021-3166

An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename…

No fix yet
Fix from $1,950 2021-01-18
Onedev CRITICAL 9.8
CVE-2021-21245

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputSt…

Fix: 4.0.3+
Fix from $2,300 2021-01-15
Rock Rms CRITICAL 9.8
CVE-2019-18643

Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanis…

Fix: 8.10 / 9.4+
Fix from $2,300 2021-01-07
Backup Exec HIGH 8.8
CVE-2020-36167

An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it …

Fix: 20.0.1188.2734 / 21.0.1200.1217+
Fix from $1,950 2021-01-06
Cloud Pak System MEDIUM 6.7
CVE-2020-4928

IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extent…

Fix: 2.3.3.3+
Fix from $1,600 2021-01-04
Divi HIGH 8.8
CVE-2020-35945

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contri…

Fix: 4.5.3+
Fix from $1,950 2021-01-01
Quiz And Survey Master CRITICAL 9.8
CVE-2020-35949

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload …

Fix: 7.0.1+
Fix from $2,300 2021-01-01
Nms300 Firmware CRITICAL 9.8
CVE-2020-35797

NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.

Fix: 1.6.0.27+
Fix from $2,300 2020-12-30
Hedgedoc HIGH 7.5
CVE-2020-26286

HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitr…

Fix: 1.7.1+
Fix from $1,950 2020-12-29
Gift Cards HIGH 8.8
CVE-2020-35627

Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary …

No fix yet
Fix from $1,950 2020-12-28
Online Matrimonial Project HIGH 8.8
CVE-2020-27397

Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain rem…

No fix yet
Fix from $1,950 2020-12-23
Jaws HIGH 7.2
CVE-2020-35657

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive …

Fix: after 1.8.0
Fix from $1,950 2020-12-23
Jaws HIGH 7.2
CVE-2020-35656

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=I…

Fix: after 1.8.0
Fix from $1,950 2020-12-23
Business Workflow HIGH 8.8
CVE-2020-26174

tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this …

Fix: 1.18.1+
Fix from $1,950 2020-12-18
Contact Form 7 CRITICAL 10.0
CVE-2020-35489EPSS 89%

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filenam…

Fix: 5.3.2+
Fix from $2,300 2020-12-17
Kps2204 6 Port Managed Din Rail Programmable Serial Device Firmware CRITICAL 9.8
CVE-2020-25010

An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 all…

Mitigation only
Fix from $2,300 2020-12-17
Irfanview HIGH 7.5
CVE-2020-35133

irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.

No fix yet
Fix from $1,950 2020-12-16
Pluck HIGH 7.2
CVE-2020-29607EPSS 33%

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "man…

Fix: 4.7.13+
Fix from $1,950 2020-12-16
Alumni Management System HIGH 7.2
CVE-2020-28072

A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in t…

No fix yet
Fix from $1,950 2020-12-15
Netweaver Application Server Java MEDIUM 6.5
CVE-2020-26826

Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) …

Mitigation only
Fix from $1,600 2020-12-09
Disclosure Management MEDIUM 6.4
CVE-2020-26828

SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some f…

Mitigation only
Fix from $1,600 2020-12-09
Imcat HIGH 7.2
CVE-2020-23520

imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.

No fix yet
Fix from $1,950 2020-12-09
Kirby CRITICAL 9.1
CVE-2020-26255

Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Pan…

Fix: 2.5.14 / 3.4.5+
Fix from $2,300 2020-12-08
Incomcms CRITICAL 9.8
CVE-2020-29597EPSS 71%

IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to up…

No fix yet
Fix from $2,300 2020-12-07
Openclinic HIGH 7.2
CVE-2020-28939

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (wit…

No fix yet
Fix from $1,950 2020-12-03
Outsystems MEDIUM 6.5
CVE-2020-29441

An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In…

Fix: 10.0.1019.0+
Fix from $1,600 2020-11-30