Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2022-20743 A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to … Secure Firewall Management Center 6.4.0.15 / 6.6.5.2+ Fix from $1,9502022-05-03 HIGH 7.2 CVE-2022-1273 The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload … Import Wp 2.4.6+ Fix from $1,9502022-05-02 HIGH 8.8 CVE-2022-29451 Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows at… Rara One Click Demo Import 1.3.0+ Fix from $1,9502022-04-29 CRITICAL 9.8 CVE-2021-43934 Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentia… Smartptt Scada Mitigation only Fix from $2,3002022-04-28 CRITICAL 9.8 CVE-2021-41921 novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. Novel Plus No fix yet Fix from $2,3002022-04-28 HIGH 8.8 CVE-2022-28525 ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. Ed01 Cms Mitigation only Fix from $1,9502022-04-26 HIGH 8.8 CVE-2022-28528 bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. Bloofoxcms No fix yet Fix from $1,9502022-04-26 MEDIUM 6.1 CVE-2021-26628 Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a spe… Maxboard 1.9.6.1+ Fix from $1,6002022-04-26 CRITICAL 9.8 CVE-2022-27468 Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to … Monsta Ftp No fix yet Fix from $2,3002022-04-26 HIGH 7.8 CVE-2022-22392 IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could re… Planning Analytics Workspace Mitigation only Fix from $1,9502022-04-25 HIGH 8.0 CVE-2021-39040 IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use o… Planning Analytics Workspace Mitigation only Fix from $1,9502022-04-25 HIGH 8.8 CVE-2021-4225 The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attem… Sp Project \& Document Manager 4.24+ Fix from $1,9502022-04-25 HIGH 8.8 CVE-2022-28053 Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to exec… Typemill No fix yet Fix from $1,9502022-04-25 HIGH 8.8 CVE-2022-28440 An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. Ucms No fix yet Fix from $1,9502022-04-21 CRITICAL 9.8 CVE-2022-28021EPSS 24% Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. Purchase Order Management System No fix yet Fix from $2,3002022-04-21 HIGH 8.8 CVE-2022-27478EPSS 20% Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin. Victor Cms No fix yet Fix from $1,9502022-04-21 CRITICAL 9.8 CVE-2022-27862 Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and … Vikbooking Hotel Booking Engine \& Property Management System Plugin after 1.5.3 Fix from $2,3002022-04-19 HIGH 8.8 CVE-2021-4096 The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for… Fancy Product Designer after 4.7.5 Fix from $1,9502022-04-19 HIGH 8.8 CVE-2022-1329EPSS 93% The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check … Website Builder after 3.6.2 Fix from $1,9502022-04-19 CRITICAL 9.0 CVE-2022-1345 Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the u… Organizr 2.1.1810+ Fix from $2,3002022-04-13 CRITICAL 9.8 CVE-2022-27262 An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file. Skipper Mitigation only Fix from $2,3002022-04-12 CRITICAL 9.8 CVE-2022-27263 An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file. Strapi No fix yet Fix from $2,3002022-04-12 CRITICAL 9.8 CVE-2022-27952 An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG f… Payload No fix yet Fix from $2,3002022-04-12 CRITICAL 9.8 CVE-2022-28397 An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. … Ghost Mitigation only Fix from $2,3002022-04-12 CRITICAL 9.8 CVE-2022-27139 An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary code via a crafted SVG file. … Ghost No fix yet Fix from $2,3002022-04-12 CRITICAL 9.8 CVE-2022-27140 An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted… Express Fileupload No fix yet Fix from $2,3002022-04-12 CRITICAL 9.8 CVE-2022-27260 An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG … Buttercms Mitigation only Fix from $2,3002022-04-12 HIGH 7.5 CVE-2022-27261 An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite… Express Fileupload No fix yet Fix from $1,9502022-04-12 MEDIUM 5.3 CVE-2022-24837 HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version 1.9.1 and later have an enum… Hedgedoc 1.9.3+ Fix from $1,6002022-04-11 HIGH 7.2 CVE-2022-1008 The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload ar… One Click Demo Import 3.1.0+ Fix from $1,9502022-04-11