Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2021-45808 jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server. Jpress Mitigation only Fix from $1,9502022-01-19 CRITICAL 9.8 CVE-2021-46013 An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability t… Free School Management Software No fix yet Fix from $2,3002022-01-18 HIGH 7.8 CVE-2022-0263 Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7. Pimcore 10.2.7+ Fix from $1,9502022-01-18 CRITICAL 9.8 CVE-2021-38697 SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which … Saraban No fix yet Fix from $2,3002022-01-18 HIGH 7.2 CVE-2021-41550 Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. Connection Broker Mitigation only Fix from $1,9502022-01-18 HIGH 7.2 CVE-2022-0242 Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. Crater 6.0+ Fix from $1,9502022-01-17 HIGH 8.8 CVE-2021-33828 The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a pu… Files Antivirus 1.0.0+ Fix from $1,9502022-01-15 HIGH 8.8 CVE-2021-34995EPSS 69% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio… Commcell Mitigation only Fix from $1,9502022-01-13 HIGH 8.8 CVE-2021-34997 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio… Commcell Mitigation only Fix from $1,9502022-01-13 CRITICAL 9.8 CVE-2021-45411 In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbit… Printable Staff Id Card Creator System No fix yet Fix from $2,3002022-01-12 HIGH 8.8 CVE-2021-44651EPSS 5% Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper… Manageengine Cloud Security Plus 4.1+ Fix from $1,9502022-01-12 HIGH 8.8 CVE-2021-4080 crater is vulnerable to Unrestricted Upload of File with Dangerous Type Crater 6.0.0+ Fix from $1,9502022-01-12 HIGH 8.8 CVE-2021-43973 An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitra… Sysaid Patch available Fix from $1,9502022-01-11 HIGH 7.2 CVE-2021-46079 An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious file… Vehicle Service Management System after 1.0 Fix from $1,9502022-01-06 HIGH 8.8 CVE-2021-46076 Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints … Vehicle Service Management System No fix yet Fix from $1,9502022-01-06 CRITICAL 9.8 CVE-2021-44031 An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a… Kace Desktop Authority 11.2+ Fix from $2,3002021-12-22 HIGH 7.5 CVE-2021-24981 The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell upl… Directorist 7.0.6.2+ Fix from $1,9502021-12-21 HIGH 7.2 CVE-2021-35244EPSS 6% The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An… Orion Platform 2020.2.6+ Fix from $1,9502021-12-20 CRITICAL 9.8 CVE-2021-44159 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files w… Gcb Doctor 2021-09-16+ Fix from $2,3002021-12-20 CRITICAL 9.8 CVE-2021-44164 Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allows a remote attacker to by-pa… Qb Smart Service Robot Mitigation only Fix from $2,3002021-12-20 HIGH 8.8 CVE-2021-23814 This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type wh… Laravel Filemanager Mitigation only Fix from $1,9502021-12-17 CRITICAL 9.8 CVE-2021-41560EPSS 11% OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. Opencats after 0.9.6 Fix from $2,3002021-12-15 HIGH 8.8 CVE-2021-41870 An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type… Remote View Pro Firmware Mitigation only Fix from $1,9502021-12-15 HIGH 8.8 CVE-2021-43829EPSS 59% PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle uploa… Patrowlmanager 1.7.7+ Fix from $1,9502021-12-14 CRITICAL 9.8 CVE-2021-40883 A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. Emlog No fix yet Fix from $2,3002021-12-14 CRITICAL 9.8 CVE-2021-43117 fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access. Fastadmin No fix yet Fix from $2,3002021-12-13 HIGH 8.1 CVE-2021-27984 In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files. Pluck No fix yet Fix from $1,9502021-12-10 HIGH 8.8 CVE-2021-36719 PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to up… Mail Secure 5.2.1+ Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-27860 KEVEPSS 40% A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a re… Ipvpn Firmware Mitigation only Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-42125EPSS 82% An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dan… Avalanche 6.3.3+ Fix from $1,9502021-12-07