Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2021-29699
IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excute…
Security Verify Access
Patch available
HIGH 8.8
CVE-2021-36121
An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestri…
Sharecare
Mitigation only
CRITICAL 9.8
CVE-2021-30118EPSS 60%
An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and …
Vsa
9.5.5+
HIGH 8.8
CVE-2021-28931
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zi…
Fork Cms
Mitigation only
CRITICAL 9.8
CVE-2021-32538
ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files with…
Artware Cms
2021-01-08+
CRITICAL 9.8
CVE-2021-34623
A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possib…
Profilepress
after 3.1.3
CRITICAL 9.8
CVE-2021-34624EPSS 7%
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible…
Profilepress
after 3.1.3
CRITICAL 9.8
CVE-2020-22249
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a m…
Phplist
No fix yet
HIGH 8.1
CVE-2021-20104
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded wit…
Machform
16+
CRITICAL 9.8
CVE-2021-34427EPSS 58%
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT v…
Business Intelligence And Reporting Tools
after 4.8.0
CRITICAL 9.8
CVE-2021-34074EPSS 7%
PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a rel…
Pandora Fms
after 754
CRITICAL 9.8
CVE-2020-21786
In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.
Ibos
No fix yet
CRITICAL 9.8
CVE-2020-21787
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
Crmeb
No fix yet
HIGH 7.2
CVE-2021-28976EPSS 8%
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
Getsimplecms
3.3.15+
CRITICAL 9.8
CVE-2010-1433
Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in…
Joomla\!
after 1.5.15
CRITICAL 9.8
CVE-2021-24376
The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" f…
Autoptimize
2.7.8+
CRITICAL 9.8
CVE-2021-24370EPSS 47%
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code executi…
Fancy Product Designer
4.6.9+
CRITICAL 9.8
CVE-2020-19510
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
Textpattern
No fix yet
HIGH 8.8
CVE-2020-36388
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive.
Civicrm
5.21.3 / 5.24.3+
CRITICAL 9.8
CVE-2013-20002
Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/the…
Framework
1.2.2+
HIGH 8.8
CVE-2021-32243
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
Fogproject
No fix yet
HIGH 8.1
CVE-2021-34551
PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
Fedora
6.5.0+
CRITICAL 9.8
CVE-2020-35760
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
Bloofoxcms
No fix yet
HIGH 8.8
CVE-2021-27489
ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow …
Defibrillator Dashboard
2.2+
HIGH 8.8
CVE-2021-34128
LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive co…
Laiketui
No fix yet
CRITICAL 9.8
CVE-2020-7864
Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz D…
Dext5 Editor
3.5.1405747.1100.03+
CRITICAL 9.8
CVE-2021-23394EPSS 19%
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only…
Elfinder
2.1.58+
HIGH 8.8
CVE-2021-26828 KEVEPSS 39%
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via …
Scadabr
after 1.12.4
CRITICAL 9.8
CVE-2021-26473
In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to wri…
Bdr Suite
4.2.0.1+
HIGH 7.2
CVE-2021-3277EPSS 55%
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-in…
Nagios Xi
after 5.7.5