Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2021-44664EPSS 13%
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a malici…
Xerte
after 3.9
HIGH 8.8
CVE-2022-25360
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. Th…
Fireware
12.1.3 / 12.5.9+
HIGH 7.2
CVE-2022-23043
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extens…
Zenario
Patch available
HIGH 8.8
CVE-2021-44967EPSS 14%
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious…
Limesurvey
No fix yet
CRITICAL 9.8
CVE-2022-24553
An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execut…
Zfaka
after 1.4.5
HIGH 8.8
CVE-2022-23375EPSS 20%
WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form…
Wikidocs
No fix yet
HIGH 7.8
CVE-2022-0409
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.
Showdoc
2.10.2+
CRITICAL 9.8
CVE-2021-46036
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.
Mcms
No fix yet
CRITICAL 9.8
CVE-2022-24984
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executabl…
Jqueryform
2022-02-05+
CRITICAL 9.8
CVE-2022-23390
An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
Bbs Forum
after 5.3
CRITICAL 9.8
CVE-2021-22803
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, w…
Interactive Graphical Scada System Data Collector
after 15.0.0.21243
CRITICAL 9.8
CVE-2020-13675
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which cause…
Drupal
8.9.19 / 9.1.13+
HIGH 7.2
CVE-2022-23048
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. Af…
Exponent Cms
No fix yet
HIGH 7.5
CVE-2021-37194
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web …
Comos
10.3.3.3 / 10.4.1+
HIGH 8.8
CVE-2021-46360EPSS 9%
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP sh…
Composr
after 10.0.39
HIGH 8.8
CVE-2022-24676
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
Hybbs2
2.3.3+
MEDIUM 6.5
CVE-2021-24947
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in…
Responsive Vector Maps
6.4.2+
MEDIUM 5.4
CVE-2022-0472
Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.
Laracom
2.0.9+
CRITICAL 9.8
CVE-2022-23329EPSS 14%
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploadin…
Jspxcms
No fix yet
HIGH 8.8
CVE-2022-24262
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to exe…
Voipmonitor
24.96+
CRITICAL 9.8
CVE-2021-46428
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parame…
Simple Chatbot Application
No fix yet
HIGH 8.8
CVE-2021-46097
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log
Dolphinphp
No fix yet
HIGH 7.2
CVE-2021-46115
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attacke…
Jpress
No fix yet
HIGH 7.2
CVE-2021-46116
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function throug…
Jpress
No fix yet
CRITICAL 9.8
CVE-2021-46386
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingso…
Mcms
after 5.2.5
HIGH 8.8
CVE-2021-44123
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a d…
Spip
Patch available
CRITICAL 9.8
CVE-2021-46033
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
Forestblog
No fix yet
HIGH 8.8
CVE-2021-46113
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the…
Kea Hotel Erp
No fix yet
CRITICAL 9.8
CVE-2022-23315
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
Mcms
No fix yet
CRITICAL 9.8
CVE-2022-22929
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary cod…
Mcms
No fix yet