Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2021-44664EPSS 13% An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a malici… Xerte after 3.9 Fix from $1,9502022-02-24 HIGH 8.8 CVE-2022-25360 WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. Th… Fireware 12.1.3 / 12.5.9+ Fix from $1,9502022-02-24 HIGH 7.2 CVE-2022-23043 Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extens… Zenario Patch available Fix from $1,9502022-02-24 HIGH 8.8 CVE-2021-44967EPSS 14% A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious… Limesurvey No fix yet Fix from $1,9502022-02-24 CRITICAL 9.8 CVE-2022-24553 An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execut… Zfaka after 1.4.5 Fix from $2,3002022-02-21 HIGH 8.8 CVE-2022-23375EPSS 20% WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form… Wikidocs No fix yet Fix from $1,9502022-02-19 HIGH 7.8 CVE-2022-0409 Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2. Showdoc 2.10.2+ Fix from $1,9502022-02-19 CRITICAL 9.8 CVE-2021-46036 An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code. Mcms No fix yet Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2022-24984 Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executabl… Jqueryform 2022-02-05+ Fix from $2,3002022-02-16 CRITICAL 9.8 CVE-2022-23390 An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files. Bbs Forum after 5.3 Fix from $2,3002022-02-14 CRITICAL 9.8 CVE-2021-22803 A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, w… Interactive Graphical Scada System Data Collector after 15.0.0.21243 Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2020-13675 Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which cause… Drupal 8.9.19 / 9.1.13+ Fix from $2,3002022-02-11 HIGH 7.2 CVE-2022-23048 Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. Af… Exponent Cms No fix yet Fix from $1,9502022-02-09 HIGH 7.5 CVE-2021-37194 A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web … Comos 10.3.3.3 / 10.4.1+ Fix from $1,9502022-02-09 HIGH 8.8 CVE-2021-46360EPSS 9% Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP sh… Composr after 10.0.39 Fix from $1,9502022-02-09 HIGH 8.8 CVE-2022-24676 update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive. Hybbs2 2.3.3+ Fix from $1,9502022-02-09 MEDIUM 6.5 CVE-2021-24947 The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in… Responsive Vector Maps 6.4.2+ Fix from $1,6002022-02-07 MEDIUM 5.4 CVE-2022-0472 Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9. Laracom 2.0.9+ Fix from $1,6002022-02-04 CRITICAL 9.8 CVE-2022-23329EPSS 14% A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploadin… Jspxcms No fix yet Fix from $2,3002022-02-04 HIGH 8.8 CVE-2022-24262 The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, allowing remote attackers to exe… Voipmonitor 24.96+ Fix from $1,9502022-02-04 CRITICAL 9.8 CVE-2021-46428 A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parame… Simple Chatbot Application No fix yet Fix from $2,3002022-01-27 HIGH 8.8 CVE-2021-46097 Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log Dolphinphp No fix yet Fix from $1,9502022-01-27 HIGH 7.2 CVE-2021-46115 jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attacke… Jpress No fix yet Fix from $1,9502022-01-26 HIGH 7.2 CVE-2021-46116 jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function throug… Jpress No fix yet Fix from $1,9502022-01-26 CRITICAL 9.8 CVE-2021-46386 File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingso… Mcms after 5.2.5 Fix from $2,3002022-01-26 HIGH 8.8 CVE-2021-44123 SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a d… Spip Patch available Fix from $1,9502022-01-26 CRITICAL 9.8 CVE-2021-46033 In ForestBlog, as of 2021-12-28, File upload can bypass verification. Forestblog No fix yet Fix from $2,3002022-01-25 HIGH 8.8 CVE-2021-46113 In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the… Kea Hotel Erp No fix yet Fix from $1,9502022-01-25 CRITICAL 9.8 CVE-2022-23315 MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do. Mcms No fix yet Fix from $2,3002022-01-21 CRITICAL 9.8 CVE-2022-22929 MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary cod… Mcms No fix yet Fix from $2,3002022-01-21