Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2021-37921EPSS 11% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37923EPSS 11% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37924EPSS 11% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37926EPSS 74% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37928EPSS 10% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37929EPSS 10% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37930EPSS 10% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-37931EPSS 10% Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 CRITICAL 9.8 CVE-2021-3832 Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenticated attacker could abuse th… Integria Ims Mitigation only Fix from $2,3002021-10-07 HIGH 7.5 CVE-2021-40324EPSS 69% Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. Cobbler after 3.3.0 Fix from $1,9502021-10-04 CRITICAL 9.8 CVE-2021-41290 ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can r… Ecs Router Controller Ecs Firmware Mitigation only Fix from $2,3002021-09-30 HIGH 7.5 CVE-2021-37105 There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be upload… Fusioncompute Mitigation only Fix from $1,9502021-09-28 MEDIUM 6.5 CVE-2020-20691 An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploading crafte… Monstra Cms No fix yet Fix from $1,6002021-09-27 CRITICAL 9.8 CVE-2021-37761EPSS 10% Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-09-27 CRITICAL 9.8 CVE-2021-37539EPSS 93% Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-09-27 CRITICAL 9.8 CVE-2021-26794 Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file. Frogcms No fix yet Fix from $2,3002021-09-23 HIGH 8.8 CVE-2021-37741 ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities. Manageengine Admanager Plus 7.1+ Fix from $1,9502021-09-21 HIGH 7.2 CVE-2021-24663 The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing h… Simple Schools Staff Directory after 1.1 Fix from $1,9502021-09-20 HIGH 7.2 CVE-2020-21483 An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to … Jizhicms No fix yet Fix from $1,9502021-09-15 CRITICAL 9.8 CVE-2020-21322 An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file. Feehicms after 2.0.8 Fix from $2,3002021-09-15 HIGH 7.2 CVE-2020-21481 An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a … Rgcms No fix yet Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-33698 SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script files) without the proper file… Business One Patch available Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-40845 The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom Scripts section a… Alphacom Xe Audio Server after 11.2.3.10 Fix from $1,9502021-09-15 CRITICAL 9.8 CVE-2021-36581 Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the e… Kooboo Cms Mitigation only Fix from $2,3002021-09-14 CRITICAL 9.8 CVE-2021-36582 In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the v… Kooboo Cms Mitigation only Fix from $2,3002021-09-14 HIGH 7.8 CVE-2020-20672 An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file. Kitecms No fix yet Fix from $1,9502021-09-13 HIGH 8.8 CVE-2020-20670 An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file. Zkeacms No fix yet Fix from $1,9502021-09-13 HIGH 8.8 CVE-2021-24620 The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable D… Simple E Commerce Shopping Cart after 2.2.5 Fix from $1,9502021-09-13 CRITICAL 9.8 CVE-2021-24493 The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have a… Shopp after 1.4 Fix from $2,3002021-09-13 MEDIUM 6.8 CVE-2021-24490 The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arb… Email Artillery after 4.1 Fix from $1,6002021-09-13