Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.1 CVE-2021-42133 An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform… Avalanche 6.3.3+ Fix from $1,9502021-12-07 CRITICAL 9.8 CVE-2021-43936EPSS 36% The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the … Webhmi Firmware 4.1+ Fix from $2,3002021-12-06 HIGH 8.8 CVE-2021-23562 This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a u… Plupload 2.3.9+ Fix from $1,9502021-12-03 HIGH 7.8 CVE-2020-29176 An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file. Z Blogphp Mitigation only Fix from $1,9502021-12-02 CRITICAL 9.8 CVE-2021-42099EPSS 7% Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. Manageengine M365 Manager Plus Mitigation only Fix from $2,3002021-11-30 HIGH 8.8 CVE-2021-42123 Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functi… Topease after 7.1.27 Fix from $1,9502021-11-30 CRITICAL 9.8 CVE-2021-44093 A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the… Zrlog No fix yet Fix from $2,3002021-11-28 HIGH 7.8 CVE-2021-44094 ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file Zrlog No fix yet Fix from $1,9502021-11-28 HIGH 7.2 CVE-2021-22968 A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versio… Concrete Cms 8.5.7+ Fix from $1,9502021-11-19 HIGH 8.8 CVE-2021-42362EPSS 80% The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/sr… Wordpress Popular Posts after 5.3.2 Fix from $1,9502021-11-17 MEDIUM 6.1 CVE-2021-39222 Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) … Talk 10.0.7 / 10.1.4+ Fix from $1,6002021-11-15 HIGH 8.8 CVE-2021-42839 Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attacke… Webopac Mitigation only Fix from $1,9502021-11-15 CRITICAL 9.8 CVE-2021-43617EPSS 20% Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAtt… Framework after 8.70.2 Fix from $2,3002021-11-14 MEDIUM 5.7 CVE-2021-3915 bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type Bookstack 21.10.3+ Fix from $1,6002021-11-13 CRITICAL 9.8 CVE-2021-41833EPSS 8% Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. Manageengine Patch Connect Plus 9.0.0+ Fix from $2,3002021-11-11 HIGH 8.8 CVE-2020-23572 BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attacker… Beescms No fix yet Fix from $1,9502021-11-08 CRITICAL 9.8 CVE-2021-28023 Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by … Servicetonic 9.0.035937+ Fix from $2,3002021-11-08 HIGH 8.8 CVE-2021-31599 An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows th… Vantara Pentaho after 9.1.0.0 Fix from $1,9502021-11-08 HIGH 7.2 CVE-2021-34685 UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated u… Vantara Pentaho after 9.1.0.0 Fix from $1,9502021-11-08 CRITICAL 9.8 CVE-2021-42669EPSS 23% A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar throu… Engineers Online Portal No fix yet Fix from $2,3002021-11-05 CRITICAL 9.8 CVE-2020-18261 An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. Ed01 Cms No fix yet Fix from $2,3002021-11-03 CRITICAL 9.8 CVE-2021-26740 Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code. Doyocms No fix yet Fix from $2,3002021-11-01 HIGH 8.8 CVE-2021-38847 S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Admin panel. This vulnerability … S Cart after 6.4.1 Fix from $1,9502021-11-01 HIGH 7.5 CVE-2018-25019 The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment… Learndash after 2.5.4 Fix from $1,9502021-11-01 CRITICAL 9.8 CVE-2021-41646EPSS 7% Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypass… Online Reviewer System No fix yet Fix from $2,3002021-10-29 CRITICAL 9.8 CVE-2021-41643 Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. Church Management System No fix yet Fix from $2,3002021-10-29 CRITICAL 9.8 CVE-2021-41644 Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses th… Online Food Ordering System No fix yet Fix from $2,3002021-10-29 HIGH 8.8 CVE-2021-41645 Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to injec… Budget And Expense Tracker System No fix yet Fix from $1,9502021-10-29 HIGH 7.2 CVE-2021-41675 A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, … E Negosyo System No fix yet Fix from $1,9502021-10-29 CRITICAL 9.8 CVE-2021-36547 A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary comman… Mara Cms No fix yet Fix from $2,3002021-10-28