Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2021-36548
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows a…
Monstra
No fix yet
MEDIUM 6.6
CVE-2021-3745
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
Flatcore Cms
2.1.0+
MEDIUM 6.5
CVE-2021-3906
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
Bookstack
21.10.1+
HIGH 8.8
CVE-2021-37221
A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create opti…
Customer Relationship Management System
No fix yet
HIGH 8.8
CVE-2021-37372
Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by upd…
Online Student Admission System
No fix yet
HIGH 7.2
CVE-2021-40344EPSS 66%
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary exten…
Nagios Xi
No fix yet
MEDIUM 6.5
CVE-2021-41178
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes a…
Server
20.0.13 / 21.0.5+
MEDIUM 5.4
CVE-2021-39221
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored …
Contacts
4.0.3+
HIGH 7.8
CVE-2020-36485
Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vul…
Playable
No fix yet
HIGH 8.8
CVE-2020-23043
Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers …
Air Sender
No fix yet
HIGH 8.8
CVE-2021-42840EPSS 59%
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account …
Suitecrm
7.11.19+
CRITICAL 9.8
CVE-2021-41745
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
Showdoc
Mitigation only
CRITICAL 9.1
CVE-2021-38471
There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.
Versiondog
8.0.0+
HIGH 7.2
CVE-2021-39352EPSS 56%
The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemo…
Catch Themes Demo Import
after 1.7
HIGH 8.8
CVE-2021-3846
firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type
Firefly Iii
5.6.2+
HIGH 7.2
CVE-2021-38484
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicio…
Ir615 Firmware
Mitigation only
HIGH 8.8
CVE-2021-38346
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the …
Brizy Page Builder
after 2.3.11
CRITICAL 9.8
CVE-2021-42342EPSS 59%
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without bein…
Goahead
5.1.5+
HIGH 8.8
CVE-2021-20130EPSS 33%
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in…
Manageengine Admanager Plus
7.1+
HIGH 8.8
CVE-2021-20131EPSS 17%
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in…
Manageengine Admanager Plus
7.1+
CRITICAL 9.8
CVE-2021-20125
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect…
Vigorconnect
No fix yet
HIGH 7.2
CVE-2021-40188
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions…
Phpfusion
No fix yet
HIGH 7.2
CVE-2021-40189
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], wh…
Phpfusion
No fix yet
HIGH 8.8
CVE-2021-39317
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_insta…
Access Demo Importer
1.0.7+
HIGH 8.8
CVE-2021-41919
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is workin…
Webtareas
after 2.4
CRITICAL 9.8
CVE-2021-41566
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary co…
Tadtools
3.2.2+
CRITICAL 9.8
CVE-2021-37762EPSS 8%
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
Manageengine Admanager Plus
7.1+
CRITICAL 9.8
CVE-2021-37918EPSS 74%
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Manageengine Admanager Plus
7.1+
CRITICAL 9.8
CVE-2021-37919EPSS 11%
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Manageengine Admanager Plus
7.1+
CRITICAL 9.8
CVE-2021-37920EPSS 11%
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Manageengine Admanager Plus
7.1+