Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.5 CVE-2022-0959 A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually uploa… Pgadmin 4 6.7+ Fix from $1,6002022-03-16 CRITICAL 9.8 CVE-2022-25487EPSS 54% Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php. Atomcms No fix yet Fix from $2,3002022-03-15 CRITICAL 9.8 CVE-2022-25495 The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a c… Cuppacms No fix yet Fix from $2,3002022-03-15 MEDIUM 6.1 CVE-2022-0951 File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. Showdoc after 2.10.3 Fix from $1,6002022-03-15 MEDIUM 5.4 CVE-2022-0950 Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4. Showdoc after 2.10.3 Fix from $1,6002022-03-15 MEDIUM 5.4 CVE-2022-0945 Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4. Showdoc after 2.10.3 Fix from $1,6002022-03-15 MEDIUM 6.1 CVE-2022-24749 Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-… Sylius 1.9.10 / 1.10.11+ Fix from $1,6002022-03-14 MEDIUM 5.4 CVE-2022-0962 Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. Showdoc 2.10.4+ Fix from $1,6002022-03-14 MEDIUM 5.4 CVE-2022-0960 Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4. Showdoc 2.10.4+ Fix from $1,6002022-03-14 HIGH 7.2 CVE-2021-42171 Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, … Zenario No fix yet Fix from $1,9502022-03-14 CRITICAL 9.8 CVE-2021-25003EPSS 56% The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on t… Wpcargo Track \& Trace 6.9.0+ Fix from $2,3002022-03-14 HIGH 7.2 CVE-2022-24387 With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml f… Smartertrack 100.0.8075+ Fix from $1,9502022-03-14 MEDIUM 6.7 CVE-2022-0921 Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12. Microweber 1.2.12+ Fix from $1,6002022-03-11 HIGH 8.8 CVE-2021-44673EPSS 9% A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell … Croogo No fix yet Fix from $1,9502022-03-10 HIGH 7.2 CVE-2022-26521EPSS 10% Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Me… Abantecart after 1.3.2 Fix from $1,9502022-03-10 CRITICAL 9.8 CVE-2022-24652 sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution … Sentcms No fix yet Fix from $2,3002022-03-10 CRITICAL 9.8 CVE-2022-24651 sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution … Sentcms No fix yet Fix from $2,3002022-03-10 HIGH 8.8 CVE-2021-43970 An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begin… Quicklert No fix yet Fix from $1,9502022-03-10 HIGH 7.2 CVE-2022-0440 The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin… Catch Themes Demo Import 2.1.1+ Fix from $1,9502022-03-07 MEDIUM 5.4 CVE-2021-24960 The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as… Wordpress File Upload 4.16.3+ Fix from $1,6002022-03-07 HIGH 7.2 CVE-2021-24216 The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows administrators to upload PHP files… One Stop Wp Migration 7.41+ Fix from $1,9502022-03-07 HIGH 7.8 CVE-2022-25115 A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v… Home Owners Collection Management System No fix yet Fix from $1,9502022-03-02 CRITICAL 9.8 CVE-2022-25016 Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/… Home Owners Collection Management System No fix yet Fix from $2,3002022-03-02 HIGH 8.8 CVE-2022-24251 Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function. Portfolio Mitigation only Fix from $1,9502022-03-01 HIGH 8.8 CVE-2022-24252 An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrar… Portfolio Mitigation only Fix from $1,9502022-03-01 HIGH 8.8 CVE-2022-24253 Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet. Portfolio Mitigation only Fix from $1,9502022-03-01 HIGH 8.8 CVE-2022-24254 An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbit… Portfolio Mitigation only Fix from $1,9502022-03-01 HIGH 7.2 CVE-2022-23906 CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability i… Cms Made Simple No fix yet Fix from $1,9502022-02-28 CRITICAL 9.8 CVE-2022-25411 A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file. Maxsite Cms No fix yet Fix from $2,3002022-02-28 HIGH 7.2 CVE-2022-26149EPSS 9% MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Up… Revolution after 2.8.3 Fix from $1,9502022-02-26