Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2021-22937EPSS 8% A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted ar… Connect Secure 9.1+ Fix from $1,9502021-08-16 CRITICAL 9.8 CVE-2020-18704 Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in th… Widgy No fix yet Fix from $2,3002021-08-16 CRITICAL 9.8 CVE-2021-38753 An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the se… Simple Image Gallery Web App No fix yet Fix from $2,3002021-08-16 CRITICAL 9.8 CVE-2021-29377 Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can b… Pearadmin Think after 2.1.2 Fix from $2,3002021-08-12 HIGH 8.8 CVE-2021-38366 Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution b… Sitecore after 10.1 Fix from $1,9502021-08-12 HIGH 7.2 CVE-2020-18462 File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file. Aikcms No fix yet Fix from $1,9502021-08-12 CRITICAL 9.8 CVE-2020-20979 An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code. Ljcms No fix yet Fix from $2,3002021-08-12 CRITICAL 9.8 CVE-2020-28165 The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the serv… Zentao 12.4.2+ Fix from $2,3002021-08-12 CRITICAL 9.8 CVE-2020-21359 An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execu… Maccms No fix yet Fix from $2,3002021-08-11 HIGH 8.8 CVE-2020-21976 An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitr… Newsone Cms No fix yet Fix from $1,9502021-08-11 HIGH 7.8 CVE-2021-38305 23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its p… Yamale 3.0.8+ Fix from $1,9502021-08-09 CRITICAL 9.8 CVE-2021-24499EPSS 60% The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks… Workreap 2.2.2+ Fix from $2,3002021-08-09 CRITICAL 9.8 CVE-2020-28088 An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code. Jeecg Boot No fix yet Fix from $2,3002021-08-06 HIGH 8.8 CVE-2021-34639 Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. … Download Manager after 3.1.24 Fix from $1,9502021-08-05 HIGH 8.1 CVE-2021-32594 An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.… Fortiportal 5.2.6 / 5.3.6+ Fix from $1,9502021-08-04 HIGH 7.8 CVE-2020-19303 An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file. Hdcms No fix yet Fix from $1,9502021-08-03 CRITICAL 9.8 CVE-2020-19302 An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded fil… Vaethink No fix yet Fix from $2,3002021-08-03 CRITICAL 9.8 CVE-2021-36622 Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function … Online Covid Vaccination Scheduler System No fix yet Fix from $2,3002021-08-03 CRITICAL 9.8 CVE-2021-36623 Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE. Phone Shop Sales Management System No fix yet Fix from $2,3002021-08-03 CRITICAL 9.8 CVE-2021-25200 Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file uploa… Learning Management System No fix yet Fix from $2,3002021-07-30 HIGH 8.8 CVE-2021-36741 KEV An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 a… Officescan Mitigation only Fix from $1,9502021-07-29 HIGH 8.8 CVE-2021-37444 NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execut… Ivm Attendant after 5.12 Fix from $1,9502021-07-25 CRITICAL 9.8 CVE-2021-25203 Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\inclu… Victor Cms No fix yet Fix from $2,3002021-07-23 CRITICAL 9.8 CVE-2021-25206 Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbitrary code via the file upload… Responsive Ordering System No fix yet Fix from $2,3002021-07-23 CRITICAL 9.8 CVE-2021-25208 Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitrary code via the file upload t… Travel Management System No fix yet Fix from $2,3002021-07-23 CRITICAL 9.8 CVE-2021-25207 Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prod… E Commerce Website No fix yet Fix from $2,3002021-07-23 CRITICAL 9.8 CVE-2021-25211 Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to orderi… Online Ordering System No fix yet Fix from $2,3002021-07-22 CRITICAL 9.8 CVE-2021-25210 Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload … Alumni Management System Mitigation only Fix from $2,3002021-07-22 HIGH 8.8 CVE-2021-34619 The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and in… Stock Manager For Woocommerce after 2.5.7 Fix from $1,9502021-07-21 CRITICAL 9.8 CVE-2021-35963 The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated … Orca Hcm after 10.0 Fix from $2,3002021-07-19