Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2021-34257 Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar imag… Wpanel Cms after 4.3.1 Fix from $1,9502022-03-31 CRITICAL 9.8 CVE-2022-24136 Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an atta… Hospital Management System No fix yet Fix from $2,3002022-03-31 CRITICAL 9.8 CVE-2022-26645 A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file u… Banking System Mitigation only Fix from $2,3002022-03-30 HIGH 7.2 CVE-2022-28223 Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin. Kio Firmware after 2022-03-30 Fix from $1,9502022-03-30 CRITICAL 9.8 CVE-2021-45865 A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality. Student Attendance Management System No fix yet Fix from $2,3002022-03-29 HIGH 7.2 CVE-2021-43098 A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function. Bbs No fix yet Fix from $1,9502022-03-28 HIGH 7.2 CVE-2021-43100 A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitra… Bbs No fix yet Fix from $1,9502022-03-28 HIGH 7.2 CVE-2021-43101 A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execut… Bbs No fix yet Fix from $1,9502022-03-28 HIGH 7.2 CVE-2021-43102 A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrar… Bbs No fix yet Fix from $1,9502022-03-28 HIGH 7.2 CVE-2021-43103 A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitra… Bbs No fix yet Fix from $1,9502022-03-28 HIGH 8.8 CVE-2022-0499 The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any… Sermon Browser after 0.45.22 Fix from $1,9502022-03-28 HIGH 8.8 CVE-2021-40905 The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which … Checkmk 2.0.0+ Fix from $1,9502022-03-25 CRITICAL 9.8 CVE-2022-23880 An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a craft… Taocms No fix yet Fix from $2,3002022-03-23 CRITICAL 9.8 CVE-2022-0888EPSS 39% The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation foun… Ninja Forms File Uploads after 3.3.0 Fix from $2,3002022-03-23 CRITICAL 9.1 CVE-2022-22952 VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload v… Carbon Black App Control 8.5.14 / 8.6.6+ Fix from $2,3002022-03-23 CRITICAL 9.8 CVE-2021-27428 GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup t… Multilin B30 Firmware 8.10+ Fix from $2,3002022-03-23 HIGH 7.8 CVE-2022-1033 Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. Crater 6.0.6+ Fix from $1,9502022-03-23 HIGH 7.2 CVE-2022-1034 There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4. Showdoc 2.10.4+ Fix from $1,9502022-03-22 HIGH 8.8 CVE-2022-23346 BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues. Bigant Server Mitigation only Fix from $1,9502022-03-21 HIGH 8.8 CVE-2022-0687 The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backd… Amelia 1.0.47+ Fix from $1,9502022-03-21 HIGH 8.8 CVE-2022-0415EPSS 65% Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. Gogs 0.12.6+ Fix from $1,9502022-03-21 HIGH 7.8 CVE-2020-26007 An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a craft… Shopxo No fix yet Fix from $1,9502022-03-20 HIGH 7.8 CVE-2020-26008 The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allo… Shopxo No fix yet Fix from $1,9502022-03-20 CRITICAL 9.8 CVE-2021-39384 DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.java. Dwsurvey No fix yet Fix from $2,3002022-03-20 HIGH 7.8 CVE-2022-25581 Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code i… Classcms after 2.5 Fix from $1,9502022-03-18 HIGH 8.8 CVE-2022-25602 Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugi… Responsive Menu after 4.1.7 Fix from $1,9502022-03-18 CRITICAL 9.8 CVE-2021-45834 An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically … Opendocman Mitigation only Fix from $2,3002022-03-18 CRITICAL 9.8 CVE-2021-45835 The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through document… Online Admissions System No fix yet Fix from $2,3002022-03-18 HIGH 7.2 CVE-2022-26965EPSS 36% In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution. Pluck No fix yet Fix from $1,9502022-03-18 CRITICAL 9.8 CVE-2021-45040 The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the upl… Laravel Media Library after 2.1.6 Fix from $2,3002022-03-17