Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2020-23083 Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file t… Jeecg after 4.0 Fix from $2,3002021-05-03 CRITICAL 9.8 CVE-2020-21452 An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC… Isc2500 S Firmware Mitigation only Fix from $2,3002021-04-29 CRITICAL 9.8 CVE-2021-24240 The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manual update functionality, leadi… Business Hours Pro after 5.5.0 Fix from $2,3002021-04-22 MEDIUM 6.5 CVE-2021-30209 Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background without any security verification,… Textpattern No fix yet Fix from $1,6002021-04-15 CRITICAL 9.8 CVE-2020-29592 An issue was discovered in Orchard before 1.10. A broken access control issue in Orchard components that use the TinyMCE HTML editor's file upload al… Orchard 1.10+ Fix from $2,3002021-04-14 CRITICAL 9.9 CVE-2021-23280 Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allows an a… Intelligent Power Manager 1.68 / 1.69+ Fix from $2,3002021-04-13 CRITICAL 9.1 CVE-2021-24220 Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPr… Focusblog 2.0.0+ Fix from $2,3002021-04-12 CRITICAL 9.8 CVE-2021-24222 The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [formCadastro] is embed. The f… Wp Curriculo Vitae Free after 6.3 Fix from $2,3002021-04-12 CRITICAL 9.8 CVE-2021-24223 The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any fil… N5 Upload Form after 1.0 Fix from $2,3002021-04-12 HIGH 8.8 CVE-2021-24224 The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any se… Easy Form Builder By Bitware after 1.0 Fix from $1,9502021-04-12 HIGH 7.2 CVE-2021-20022 KEVEPSS 17% SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remot… Email Security 10.0.9.6103 / 10.0.9.6105+ Fix from $1,9502021-04-09 HIGH 8.8 CVE-2021-29641 Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .… Directus 8.8.2+ Fix from $1,9502021-04-07 CRITICAL 9.8 CVE-2021-28173 The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitra… Deltaflow 7.7+ Fix from $2,3002021-04-06 CRITICAL 9.8 CVE-2021-30149EPSS 10% Composr 10.0.36 allows upload and execution of PHP files. Composr Patch available Fix from $2,3002021-04-06 CRITICAL 9.8 CVE-2021-24212EPSS 8% The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to u… Help Scout 2.9.1+ Fix from $2,3002021-04-05 HIGH 8.8 CVE-2021-24160EPSS 8% In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would … Responsive Menu 4.0.4+ Fix from $1,9502021-04-05 CRITICAL 9.8 CVE-2021-24171 The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible t… Woocommerce Upload Files 59.4+ Fix from $2,3002021-04-05 HIGH 7.2 CVE-2021-24155EPSS 84% The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format an… Backup Guard 1.6.0+ Fix from $1,9502021-04-05 CRITICAL 9.8 CVE-2020-21585 Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module. Emlog No fix yet Fix from $2,3002021-04-02 HIGH 7.2 CVE-2020-28173 Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious … Simple College No fix yet Fix from $1,9502021-03-31 MEDIUM 6.2 CVE-2020-19642 An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recd… Wifi Mini Spy 1080p Hd Security Ip Camera Firmware No fix yet Fix from $1,6002021-03-30 CRITICAL 9.8 CVE-2021-27274EPSS 8% This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26.… Prosafe Network Management System Mitigation only Fix from $2,3002021-03-29 MEDIUM 6.5 CVE-2021-26597 An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web sit… Netact No fix yet Fix from $1,6002021-03-25 HIGH 8.6 CVE-2021-21355 TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensurin… TYPO3 8.7.40 / 9.5.25+ Fix from $1,9502021-03-23 HIGH 8.3 CVE-2021-21357 TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1 due to improper input valid… TYPO3 8.7.40 / 9.5.25+ Fix from $1,9502021-03-23 CRITICAL 9.8 CVE-2021-21347EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21350EPSS 15% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.1 CVE-2021-21351EPSS 82% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote a… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21344EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23 CRITICAL 9.8 CVE-2021-21346EPSS 76% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $2,3002021-03-23