Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2020-36141 BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' … Bloofoxcms No fix yet Fix from $1,9502021-06-04 HIGH 7.3 CVE-2021-32661 Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.… \@backstage\/plugin Techdocs 0.9.5+ Fix from $1,9502021-06-03 HIGH 8.1 CVE-2021-32660 Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versio… \@backstage\/techdocs Common 0.6.4+ Fix from $1,9502021-06-03 MEDIUM 6.5 CVE-2020-21005 WellCMS 2.0 beta3 is vulnerable to File Upload. A user can log in to the CMS background and upload a picture. Because the upload file type is control… Wellcms No fix yet Fix from $1,6002021-06-03 CRITICAL 9.8 CVE-2020-35442 FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background via Front/lib/Action/FindexAct… Fdcms No fix yet Fix from $2,3002021-06-02 HIGH 8.8 CVE-2021-29092 Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote… Photo Station 6.8.14-3500+ Fix from $1,9502021-06-01 HIGH 8.8 CVE-2021-24311 The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitrary file uploads via any auth… External Media 1.0.34+ Fix from $1,9502021-06-01 CRITICAL 9.8 CVE-2021-31703 Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user. Ichris after 5.18 Fix from $2,3002021-05-29 HIGH 8.8 CVE-2020-26678 vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a p… Vfairs Mitigation only Fix from $1,9502021-05-26 HIGH 7.2 CVE-2020-23765 A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Ad… Bludit No fix yet Fix from $1,9502021-05-21 HIGH 8.8 CVE-2021-32630 Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenti… Admidio 4.0.4+ Fix from $1,9502021-05-20 CRITICAL 9.8 CVE-2021-27459 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvali… X Stream Enhanced Xegp Firmware Mitigation only Fix from $2,3002021-05-20 CRITICAL 9.8 CVE-2021-20721 KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbit… Konawiki 2.2.4+ Fix from $2,3002021-05-20 HIGH 7.8 CVE-2021-32622 Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the loca… Matrix React Sdk 3.21.0+ Fix from $1,9502021-05-17 CRITICAL 9.8 CVE-2020-18166 Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the c… Laobancms No fix yet Fix from $2,3002021-05-14 CRITICAL 9.8 CVE-2021-24284EPSS 42% The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The su… Kaswara after 3.0.1 Fix from $2,3002021-05-14 CRITICAL 9.8 CVE-2020-20092 File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP … Articlecms No fix yet Fix from $2,3002021-05-13 CRITICAL 9.8 CVE-2020-28063 A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. Articlecms No fix yet Fix from $2,3002021-05-13 CRITICAL 9.8 CVE-2020-23790 An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5. Golo No fix yet Fix from $2,3002021-05-12 CRITICAL 9.8 CVE-2021-32089 An issue was discovered on Zebra (formerly Motorola Solutions) Fixed RFID Reader FX9500 devices. An unauthenticated attacker can upload arbitrary fil… Fx9500 Firmware Mitigation only Fix from $2,3002021-05-11 MEDIUM 6.6 CVE-2021-31207 KEVEPSS 100% Microsoft Exchange Server Security Feature Bypass Vulnerability Exchange Server Patch available Fix from $1,6002021-05-11 MEDIUM 5.3 CVE-2021-29022 In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory. Invoiceplane No fix yet Fix from $1,6002021-05-10 HIGH 8.8 CVE-2021-32094 U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files. Emissary Mitigation only Fix from $1,9502021-05-07 CRITICAL 9.8 CVE-2021-31737 emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php. Emlog No fix yet Fix from $2,3002021-05-06 CRITICAL 9.8 CVE-2021-24236EPSS 7% The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to fo… Imagements after 1.2.5 Fix from $2,3002021-05-06 HIGH 7.2 CVE-2021-24248 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forb… Business Directory Plugin Easy Listing Directories 5.11.1+ Fix from $1,9502021-05-06 HIGH 7.2 CVE-2021-24252 The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload arbitrary files, such as .ex… Event Banner after 1.3 Fix from $1,9502021-05-06 HIGH 8.8 CVE-2021-24253 The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds a listing, only checking the … Classyfrieds after 3.8 Fix from $1,9502021-05-06 HIGH 7.2 CVE-2021-24254 The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing high privilege users to upload… College Publisher Import after 0.1 Fix from $1,9502021-05-06 CRITICAL 9.8 CVE-2020-19113 Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution. Online Book Store Project In Php No fix yet Fix from $2,3002021-05-06