Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.8 CVE-2021-29699 IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excute… Security Verify Access Patch available Fix from $1,6002021-07-15 HIGH 8.8 CVE-2021-36121 An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestri… Sharecare Mitigation only Fix from $1,9502021-07-13 CRITICAL 9.8 CVE-2021-30118EPSS 60% An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and … Vsa 9.5.5+ Fix from $2,3002021-07-09 HIGH 8.8 CVE-2021-28931 Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zi… Fork Cms Mitigation only Fix from $1,9502021-07-07 CRITICAL 9.8 CVE-2021-32538 ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files with… Artware Cms 2021-01-08+ Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-34623 A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possib… Profilepress after 3.1.3 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-34624EPSS 7% A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible… Profilepress after 3.1.3 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2020-22249 Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a m… Phplist No fix yet Fix from $2,3002021-07-06 HIGH 8.1 CVE-2021-20104 Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded wit… Machform 16+ Fix from $1,9502021-06-29 CRITICAL 9.8 CVE-2021-34427EPSS 58% In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT v… Business Intelligence And Reporting Tools after 4.8.0 Fix from $2,3002021-06-25 CRITICAL 9.8 CVE-2021-34074EPSS 7% PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a rel… Pandora Fms after 754 Fix from $2,3002021-06-25 CRITICAL 9.8 CVE-2020-21786 In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php. Ibos No fix yet Fix from $2,3002021-06-24 CRITICAL 9.8 CVE-2020-21787 CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. Crmeb No fix yet Fix from $2,3002021-06-24 HIGH 7.2 CVE-2021-28976EPSS 8% Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. Getsimplecms 3.3.15+ Fix from $1,9502021-06-23 CRITICAL 9.8 CVE-2010-1433 Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied in… Joomla\! after 1.5.15 Fix from $2,3002021-06-21 CRITICAL 9.8 CVE-2021-24376 The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" f… Autoptimize 2.7.8+ Fix from $2,3002021-06-21 CRITICAL 9.8 CVE-2021-24370EPSS 47% The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code executi… Fancy Product Designer 4.6.9+ Fix from $2,3002021-06-21 CRITICAL 9.8 CVE-2020-19510 Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php. Textpattern No fix yet Fix from $2,3002021-06-21 HIGH 8.8 CVE-2020-36388 In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR archive. Civicrm 5.21.3 / 5.24.3+ Fix from $1,9502021-06-17 CRITICAL 9.8 CVE-2013-20002 Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/the… Framework 1.2.2+ Fix from $2,3002021-06-17 HIGH 8.8 CVE-2021-32243 FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated). Fogproject No fix yet Fix from $1,9502021-06-16 HIGH 8.1 CVE-2021-34551 PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. Fedora 6.5.0+ Fix from $1,9502021-06-16 CRITICAL 9.8 CVE-2020-35760 bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files). Bloofoxcms No fix yet Fix from $2,3002021-06-16 HIGH 8.8 CVE-2021-27489 ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow … Defibrillator Dashboard 2.2+ Fix from $1,9502021-06-16 HIGH 8.8 CVE-2021-34128 LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive co… Laiketui No fix yet Fix from $1,9502021-06-15 CRITICAL 9.8 CVE-2020-7864 Parameter manipulation can bypass authentication to cause file upload and execution. This will execute the remote code. This issue affects: Raonwiz D… Dext5 Editor 3.5.1405747.1100.03+ Fix from $2,3002021-06-15 CRITICAL 9.8 CVE-2021-23394EPSS 19% The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only… Elfinder 2.1.58+ Fix from $2,3002021-06-13 HIGH 8.8 CVE-2021-26828 KEVEPSS 39% OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via … Scadabr after 1.12.4 Fix from $1,9502021-06-11 CRITICAL 9.8 CVE-2021-26473 In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to wri… Bdr Suite 4.2.0.1+ Fix from $2,3002021-06-08 HIGH 7.2 CVE-2021-3277EPSS 55% Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-in… Nagios Xi after 5.7.5 Fix from $1,9502021-06-07