Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2021-36548 A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows a… Monstra No fix yet Fix from $2,3002021-10-28 MEDIUM 6.6 CVE-2021-3745 flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type Flatcore Cms 2.1.0+ Fix from $1,6002021-10-28 MEDIUM 6.5 CVE-2021-3906 bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type Bookstack 21.10.1+ Fix from $1,6002021-10-27 HIGH 8.8 CVE-2021-37221 A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create opti… Customer Relationship Management System No fix yet Fix from $1,9502021-10-27 HIGH 8.8 CVE-2021-37372 Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by upd… Online Student Admission System No fix yet Fix from $1,9502021-10-26 HIGH 7.2 CVE-2021-40344EPSS 66% An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary exten… Nagios Xi No fix yet Fix from $1,9502021-10-26 MEDIUM 6.5 CVE-2021-41178 Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes a… Server 20.0.13 / 21.0.5+ Fix from $1,6002021-10-25 MEDIUM 5.4 CVE-2021-39221 Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored … Contacts 4.0.3+ Fix from $1,6002021-10-25 HIGH 7.8 CVE-2020-36485 Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vul… Playable No fix yet Fix from $1,9502021-10-22 HIGH 8.8 CVE-2020-23043 Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers … Air Sender No fix yet Fix from $1,9502021-10-22 HIGH 8.8 CVE-2021-42840EPSS 59% SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account … Suitecrm 7.11.19+ Fix from $1,9502021-10-22 CRITICAL 9.8 CVE-2021-41745 ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. Showdoc Mitigation only Fix from $2,3002021-10-22 CRITICAL 9.1 CVE-2021-38471 There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files. Versiondog 8.0.0+ Fix from $2,3002021-10-22 HIGH 7.2 CVE-2021-39352EPSS 56% The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemo… Catch Themes Demo Import after 1.7 Fix from $1,9502021-10-21 HIGH 8.8 CVE-2021-3846 firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type Firefly Iii 5.6.2+ Fix from $1,9502021-10-19 HIGH 7.2 CVE-2021-38484 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicio… Ir615 Firmware Mitigation only Fix from $1,9502021-10-19 HIGH 8.8 CVE-2021-38346 The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the … Brizy Page Builder after 2.3.11 Fix from $1,9502021-10-14 CRITICAL 9.8 CVE-2021-42342EPSS 59% An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without bein… Goahead 5.1.5+ Fix from $2,3002021-10-14 HIGH 8.8 CVE-2021-20130EPSS 33% ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in… Manageengine Admanager Plus 7.1+ Fix from $1,9502021-10-13 HIGH 8.8 CVE-2021-20131EPSS 17% ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in… Manageengine Admanager Plus 7.1+ Fix from $1,9502021-10-13 CRITICAL 9.8 CVE-2021-20125 An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect… Vigorconnect No fix yet Fix from $2,3002021-10-13 HIGH 7.2 CVE-2021-40188 PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions… Phpfusion No fix yet Fix from $1,9502021-10-11 HIGH 7.2 CVE-2021-40189 PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], wh… Phpfusion No fix yet Fix from $1,9502021-10-11 HIGH 8.8 CVE-2021-39317 A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_insta… Access Demo Importer 1.0.7+ Fix from $1,9502021-10-11 HIGH 8.8 CVE-2021-41919 webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is workin… Webtareas after 2.4 Fix from $1,9502021-10-08 CRITICAL 9.8 CVE-2021-41566 The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary co… Tadtools 3.2.2+ Fix from $2,3002021-10-08 CRITICAL 9.8 CVE-2021-37762EPSS 8% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37918EPSS 74% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37919EPSS 11% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37920EPSS 11% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07