Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2021-42133
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform…
Avalanche
6.3.3+
CRITICAL 9.8
CVE-2021-43936EPSS 36%
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the …
Webhmi Firmware
4.1+
HIGH 8.8
CVE-2021-23562
This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a u…
Plupload
2.3.9+
HIGH 7.8
CVE-2020-29176
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.
Z Blogphp
Mitigation only
CRITICAL 9.8
CVE-2021-42099EPSS 7%
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
Manageengine M365 Manager Plus
Mitigation only
HIGH 8.8
CVE-2021-42123
Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functi…
Topease
after 7.1.27
CRITICAL 9.8
CVE-2021-44093
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the…
Zrlog
No fix yet
HIGH 7.8
CVE-2021-44094
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
Zrlog
No fix yet
HIGH 7.2
CVE-2021-22968
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versio…
Concrete Cms
8.5.7+
HIGH 8.8
CVE-2021-42362EPSS 80%
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/sr…
Wordpress Popular Posts
after 5.3.2
MEDIUM 6.1
CVE-2021-39222
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) …
Talk
10.0.7 / 10.1.4+
HIGH 8.8
CVE-2021-42839
Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attacke…
Webopac
Mitigation only
CRITICAL 9.8
CVE-2021-43617EPSS 20%
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAtt…
Framework
after 8.70.2
MEDIUM 5.7
CVE-2021-3915
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
Bookstack
21.10.3+
CRITICAL 9.8
CVE-2021-41833EPSS 8%
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
Manageengine Patch Connect Plus
9.0.0+
HIGH 8.8
CVE-2020-23572
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attacker…
Beescms
No fix yet
CRITICAL 9.8
CVE-2021-28023
Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious user to execute JSP code by …
Servicetonic
9.0.035937+
HIGH 8.8
CVE-2021-31599
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows th…
Vantara Pentaho
after 9.1.0.0
HIGH 7.2
CVE-2021-34685
UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated u…
Vantara Pentaho
after 9.1.0.0
CRITICAL 9.8
CVE-2021-42669EPSS 23%
A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar throu…
Engineers Online Portal
No fix yet
CRITICAL 9.8
CVE-2020-18261
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.
Ed01 Cms
No fix yet
CRITICAL 9.8
CVE-2021-26740
Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.
Doyocms
No fix yet
HIGH 8.8
CVE-2021-38847
S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Admin panel. This vulnerability …
S Cart
after 6.4.1
HIGH 7.5
CVE-2018-25019
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment…
Learndash
after 2.5.4
CRITICAL 9.8
CVE-2021-41646EPSS 7%
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypass…
Online Reviewer System
No fix yet
CRITICAL 9.8
CVE-2021-41643
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
Church Management System
No fix yet
CRITICAL 9.8
CVE-2021-41644
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses th…
Online Food Ordering System
No fix yet
HIGH 8.8
CVE-2021-41645
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to injec…
Budget And Expense Tracker System
No fix yet
HIGH 7.2
CVE-2021-41675
A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, …
E Negosyo System
No fix yet
CRITICAL 9.8
CVE-2021-36547
A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary comman…
Mara Cms
No fix yet