Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2022-0959
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually uploa…
Pgadmin 4
6.7+
CRITICAL 9.8
CVE-2022-25487EPSS 54%
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
Atomcms
No fix yet
CRITICAL 9.8
CVE-2022-25495
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a c…
Cuppacms
No fix yet
MEDIUM 6.1
CVE-2022-0951
File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.
Showdoc
after 2.10.3
MEDIUM 5.4
CVE-2022-0950
Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.
Showdoc
after 2.10.3
MEDIUM 5.4
CVE-2022-0945
Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.
Showdoc
after 2.10.3
MEDIUM 6.1
CVE-2022-24749
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-…
Sylius
1.9.10 / 1.10.11+
MEDIUM 5.4
CVE-2022-0962
Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.
Showdoc
2.10.4+
MEDIUM 5.4
CVE-2022-0960
Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
Showdoc
2.10.4+
HIGH 7.2
CVE-2021-42171
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, …
Zenario
No fix yet
CRITICAL 9.8
CVE-2021-25003EPSS 56%
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on t…
Wpcargo Track \& Trace
6.9.0+
HIGH 7.2
CVE-2022-24387
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml f…
Smartertrack
100.0.8075+
MEDIUM 6.7
CVE-2022-0921
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
Microweber
1.2.12+
HIGH 8.8
CVE-2021-44673EPSS 9%
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell …
Croogo
No fix yet
HIGH 7.2
CVE-2022-26521EPSS 10%
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Me…
Abantecart
after 1.3.2
CRITICAL 9.8
CVE-2022-24652
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution …
Sentcms
No fix yet
CRITICAL 9.8
CVE-2022-24651
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution …
Sentcms
No fix yet
HIGH 8.8
CVE-2021-43970
An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begin…
Quicklert
No fix yet
HIGH 7.2
CVE-2022-0440
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin…
Catch Themes Demo Import
2.1.1+
MEDIUM 5.4
CVE-2021-24960
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as…
Wordpress File Upload
4.16.3+
HIGH 7.2
CVE-2021-24216
The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files…
One Stop Wp Migration
7.41+
HIGH 7.8
CVE-2022-25115
A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v…
Home Owners Collection Management System
No fix yet
CRITICAL 9.8
CVE-2022-25016
Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/…
Home Owners Collection Management System
No fix yet
HIGH 8.8
CVE-2022-24251
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
Portfolio
Mitigation only
HIGH 8.8
CVE-2022-24252
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrar…
Portfolio
Mitigation only
HIGH 8.8
CVE-2022-24253
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.
Portfolio
Mitigation only
HIGH 8.8
CVE-2022-24254
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbit…
Portfolio
Mitigation only
HIGH 7.2
CVE-2022-23906
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability i…
Cms Made Simple
No fix yet
CRITICAL 9.8
CVE-2022-25411
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
Maxsite Cms
No fix yet
HIGH 7.2
CVE-2022-26149EPSS 9%
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Up…
Revolution
after 2.8.3