Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2022-27115EPSS 29% In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. Elfinder Patch available Fix from $2,3002022-04-11 MEDIUM 5.4 CVE-2022-1045 Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0. Trudesk 1.2.0+ Fix from $1,6002022-04-11 CRITICAL 9.8 CVE-2022-27477 Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit. Newbee Mall No fix yet Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27129 An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file. Zbzcms Mitigation only Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27131 An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file. Zbzcms Mitigation only Fix from $2,3002022-04-10 CRITICAL 9.8 CVE-2022-27047 mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation. Mogu Blog Cms Mitigation only Fix from $2,3002022-04-08 HIGH 7.2 CVE-2021-46367EPSS 30% RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP fil… Ritecms after 3.1.0 Fix from $1,9502022-04-08 HIGH 7.2 CVE-2022-27061 AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability… Aerocms No fix yet Fix from $1,9502022-04-08 HIGH 8.8 CVE-2022-27064 Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to exec… Musical World No fix yet Fix from $1,9502022-04-08 HIGH 8.8 CVE-2022-27346 Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attac… Ecommerce Website No fix yet Fix from $1,9502022-04-08 HIGH 7.2 CVE-2022-27349 Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execu… Social Codia Sms No fix yet Fix from $1,9502022-04-08 CRITICAL 9.8 CVE-2022-27351 Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows… Zoo Management System No fix yet Fix from $2,3002022-04-08 HIGH 8.8 CVE-2022-27352 Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attac… Simple House Rental System No fix yet Fix from $1,9502022-04-08 CRITICAL 9.8 CVE-2022-27357 Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers… Ecommerce Website No fix yet Fix from $2,3002022-04-08 HIGH 8.8 CVE-2021-43430 An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan… Bigant Office Messenger 5 No fix yet Fix from $1,9502022-04-07 CRITICAL 9.8 CVE-2021-43421EPSS 43% A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload ar… Elfinder after 2.1.59 Fix from $2,3002022-04-07 HIGH 8.8 CVE-2022-26627 Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrar… Online Project Time Management System No fix yet Fix from $1,9502022-04-07 HIGH 8.8 CVE-2022-26605 eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality. Eziosuite No fix yet Fix from $1,9502022-04-06 HIGH 7.2 CVE-2022-26607 A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a cra… Baigo Cms No fix yet Fix from $1,9502022-04-06 HIGH 8.8 CVE-2022-26630 Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\db.php. Jellycms after 3.8.1 Fix from $1,9502022-04-05 CRITICAL 9.8 CVE-2021-28428 File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. … Horizontcms Patch available Fix from $2,3002022-04-05 HIGH 7.5 CVE-2022-26619 Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function. Halo No fix yet Fix from $1,9502022-04-05 HIGH 7.2 CVE-2020-28062 An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plug… Hisiphp No fix yet Fix from $1,9502022-04-04 HIGH 8.1 CVE-2022-0403 The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security… Library File Manager 5.2.3+ Fix from $1,9502022-04-04 HIGH 7.2 CVE-2022-0537 The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings … Mappress 2.73.13+ Fix from $1,9502022-04-04 HIGH 8.8 CVE-2022-27435 An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product … Ecommerce Website No fix yet Fix from $1,9502022-04-04 HIGH 8.8 CVE-2022-28062 Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and exec… Online Car Rental System No fix yet Fix from $1,9502022-04-04 HIGH 8.8 CVE-2022-27249 An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using Up… Reftree 2021.09.17+ Fix from $1,9502022-04-03 HIGH 7.5 CVE-2021-32961 A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a reques… Autosave 4.01 / 6.02.06+ Fix from $1,9502022-04-01 HIGH 7.2 CVE-2022-23155 Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can e… Wyse Management Suite after 3.5.2 Fix from $1,9502022-04-01