Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2021-22937EPSS 8%
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted ar…
Connect Secure
9.1+
CRITICAL 9.8
CVE-2020-18704
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in th…
Widgy
No fix yet
CRITICAL 9.8
CVE-2021-38753
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the se…
Simple Image Gallery Web App
No fix yet
CRITICAL 9.8
CVE-2021-29377
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can b…
Pearadmin Think
after 2.1.2
HIGH 8.8
CVE-2021-38366
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution b…
Sitecore
after 10.1
HIGH 7.2
CVE-2020-18462
File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file.
Aikcms
No fix yet
CRITICAL 9.8
CVE-2020-20979
An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.
Ljcms
No fix yet
CRITICAL 9.8
CVE-2020-28165
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the serv…
Zentao
12.4.2+
CRITICAL 9.8
CVE-2020-21359
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execu…
Maccms
No fix yet
HIGH 8.8
CVE-2020-21976
An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitr…
Newsone Cms
No fix yet
HIGH 7.8
CVE-2021-38305
23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its p…
Yamale
3.0.8+
CRITICAL 9.8
CVE-2021-24499EPSS 60%
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks…
Workreap
2.2.2+
CRITICAL 9.8
CVE-2020-28088
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
Jeecg Boot
No fix yet
HIGH 8.8
CVE-2021-34639
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. …
Download Manager
after 3.1.24
HIGH 8.1
CVE-2021-32594
An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.…
Fortiportal
5.2.6 / 5.3.6+
HIGH 7.8
CVE-2020-19303
An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.
Hdcms
No fix yet
CRITICAL 9.8
CVE-2020-19302
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded fil…
Vaethink
No fix yet
CRITICAL 9.8
CVE-2021-36622
Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function …
Online Covid Vaccination Scheduler System
No fix yet
CRITICAL 9.8
CVE-2021-36623
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
Phone Shop Sales Management System
No fix yet
CRITICAL 9.8
CVE-2021-25200
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file uploa…
Learning Management System
No fix yet
HIGH 8.8
CVE-2021-36741 KEV
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 a…
Officescan
Mitigation only
HIGH 8.8
CVE-2021-37444
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execut…
Ivm Attendant
after 5.12
CRITICAL 9.8
CVE-2021-25203
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\inclu…
Victor Cms
No fix yet
CRITICAL 9.8
CVE-2021-25206
Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload…
Responsive Ordering System
No fix yet
CRITICAL 9.8
CVE-2021-25208
Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload t…
Travel Management System
No fix yet
CRITICAL 9.8
CVE-2021-25207
Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prod…
E Commerce Website
No fix yet
CRITICAL 9.8
CVE-2021-25211
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to orderi…
Online Ordering System
No fix yet
CRITICAL 9.8
CVE-2021-25210
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload …
Alumni Management System
Mitigation only
HIGH 8.8
CVE-2021-34619
The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and in…
Stock Manager For Woocommerce
after 2.5.7
CRITICAL 9.8
CVE-2021-35963
The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated …
Orca Hcm
after 10.0