Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-27115EPSS 29%
In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.
Elfinder
Patch available
MEDIUM 5.4
CVE-2022-1045
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
Trudesk
1.2.0+
CRITICAL 9.8
CVE-2022-27477
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
Newbee Mall
No fix yet
CRITICAL 9.8
CVE-2022-27129
An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Zbzcms
Mitigation only
CRITICAL 9.8
CVE-2022-27131
An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Zbzcms
Mitigation only
CRITICAL 9.8
CVE-2022-27047
mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.
Mogu Blog Cms
Mitigation only
HIGH 7.2
CVE-2021-46367EPSS 30%
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP fil…
Ritecms
after 3.1.0
HIGH 7.2
CVE-2022-27061
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability…
Aerocms
No fix yet
HIGH 8.8
CVE-2022-27064
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to exec…
Musical World
No fix yet
HIGH 8.8
CVE-2022-27346
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attac…
Ecommerce Website
No fix yet
HIGH 7.2
CVE-2022-27349
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execu…
Social Codia Sms
No fix yet
CRITICAL 9.8
CVE-2022-27351
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows…
Zoo Management System
No fix yet
HIGH 8.8
CVE-2022-27352
Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attac…
Simple House Rental System
No fix yet
CRITICAL 9.8
CVE-2022-27357
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers…
Ecommerce Website
No fix yet
HIGH 8.8
CVE-2021-43430
An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan…
Bigant Office Messenger 5
No fix yet
CRITICAL 9.8
CVE-2021-43421EPSS 43%
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload ar…
Elfinder
after 2.1.59
HIGH 8.8
CVE-2022-26627
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrar…
Online Project Time Management System
No fix yet
HIGH 8.8
CVE-2022-26605
eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.
Eziosuite
No fix yet
HIGH 7.2
CVE-2022-26607
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a cra…
Baigo Cms
No fix yet
HIGH 8.8
CVE-2022-26630
Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php.
Jellycms
after 3.8.1
CRITICAL 9.8
CVE-2021-28428
File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. …
Horizontcms
Patch available
HIGH 7.5
CVE-2022-26619
Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.
Halo
No fix yet
HIGH 7.2
CVE-2020-28062
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plug…
Hisiphp
No fix yet
HIGH 8.1
CVE-2022-0403
The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security…
Library File Manager
5.2.3+
HIGH 7.2
CVE-2022-0537
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings …
Mappress
2.73.13+
HIGH 8.8
CVE-2022-27435
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product …
Ecommerce Website
No fix yet
HIGH 8.8
CVE-2022-28062
Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and exec…
Online Car Rental System
No fix yet
HIGH 8.8
CVE-2022-27249
An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using Up…
Reftree
2021.09.17+
HIGH 7.5
CVE-2021-32961
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a reques…
Autosave
4.01 / 6.02.06+
HIGH 7.2
CVE-2022-23155
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can e…
Wyse Management Suite
after 3.5.2