Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2020-19267 An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file. Dswjcms No fix yet Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-36440 Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdat… Showdoc No fix yet Fix from $2,3002021-09-08 CRITICAL 9.8 CVE-2020-19138EPSS 6% Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src… Dotcms after 5.2.3 Fix from $2,3002021-09-08 HIGH 8.8 CVE-2021-38841 Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page in classes… Simple Water Refilling Station Management System No fix yet Fix from $1,9502021-09-07 CRITICAL 9.8 CVE-2021-40531EPSS 33% Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quar… Sketch 75+ Fix from $2,3002021-09-06 HIGH 7.5 CVE-2021-40524 In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lea… Pure Ftpd 1.0.50+ Fix from $1,9502021-09-05 HIGH 7.2 CVE-2021-36040 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil… Adobe Commerce after 2.4.2 Fix from $1,9502021-09-01 HIGH 7.2 CVE-2021-36042 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil… Adobe Commerce after 2.4.2 Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-29907 IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force… Openpages With Watson 8.1.0.2.1 / 8.2.0.2+ Fix from $1,9502021-08-31 CRITICAL 9.8 CVE-2021-36356EPSS 54% KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary … Viaware after 2021-08 Fix from $2,3002021-08-31 CRITICAL 9.8 CVE-2021-32955EPSS 37% Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code. Diaenergie after 1.7.5 Fix from $2,3002021-08-30 CRITICAL 9.8 CVE-2021-40175EPSS 7% Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. Manageengine Log360 after 5.1 Fix from $2,3002021-08-29 CRITICAL 9.8 CVE-2020-18114 An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format. Dedecms No fix yet Fix from $2,3002021-08-27 CRITICAL 9.1 CVE-2021-33884 An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any file… Spacecom2 012u000062+ Fix from $2,3002021-08-25 CRITICAL 9.8 CVE-2021-38613 The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and a… Remkon Device Manager No fix yet Fix from $2,3002021-08-24 HIGH 7.2 CVE-2021-39608EPSS 46% Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arb… Flatcore Cms No fix yet Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39153 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39154 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39141EPSS 16% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39145 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39146EPSS 14% XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39147 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39148 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39149 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.5 CVE-2021-39151 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Fedora 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2021-39139 XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load a… Debian Linux 1.4.18+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2020-27461 A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an aut… Seopanel Patch available Fix from $1,9502021-08-20 CRITICAL 9.8 CVE-2020-18879 Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln… Bludit No fix yet Fix from $2,3002021-08-20 HIGH 7.2 CVE-2020-18886 Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'. Phpmywind No fix yet Fix from $1,9502021-08-20 CRITICAL 9.8 CVE-2021-37608EPSS 6% Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apach… Ofbiz 17.12.08+ Fix from $2,3002021-08-18