Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2021-24145EPSS 88% Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing… Modern Events Calendar Lite 5.16.5+ Fix from $1,9502021-03-18 HIGH 7.2 CVE-2021-24123 Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones fr… Powerpress 8.3.8+ Fix from $1,9502021-03-18 CRITICAL 9.8 CVE-2021-28294 Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code… Online Ordering System No fix yet Fix from $2,3002021-03-16 CRITICAL 9.8 CVE-2021-27817 A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which… Shopxo Mitigation only Fix from $2,3002021-03-15 HIGH 8.8 CVE-2021-28379EPSS 6% web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different or… Myvesta after 0.9.8-27 Fix from $1,9502021-03-15 HIGH 7.2 CVE-2020-29032 Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious co… Gatemanager 8250 Firmware 9.4.621054022+ Fix from $1,9502021-03-05 CRITICAL 9.8 CVE-2021-27964EPSS 48% SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFi… Sonlogger 6.4.1+ Fix from $2,3002021-03-05 HIGH 7.2 CVE-2020-36079 Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the upload… Zenphoto after 1.5.7 Fix from $1,9502021-02-26 CRITICAL 9.8 CVE-2021-27198EPSS 14% An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in… Myconnection Server 11.1a+ Fix from $2,3002021-02-26 HIGH 8.8 CVE-2021-20659 SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PH… Sv Cpt Mc310 Firmware 6.5+ Fix from $1,9502021-02-24 HIGH 8.0 CVE-2020-7847 The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote co… Nas I Firmware 1.4.36+ Fix from $1,9502021-02-23 CRITICAL 9.8 CVE-2021-3120EPSS 37% An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achiev… Yith Woocommerce Gift Cards 3.3.1+ Fix from $2,3002021-02-22 HIGH 8.8 CVE-2021-27513EPSS 28% The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre us… Eyesofnetwork Patch available Fix from $1,9502021-02-22 HIGH 7.2 CVE-2021-25780 An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote at… Baby Care System No fix yet Fix from $1,9502021-02-17 CRITICAL 9.8 CVE-2021-26809 PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php. Car Rental Portal No fix yet Fix from $2,3002021-02-17 HIGH 8.8 CVE-2021-22858 Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obt… Changjia Property Management System Mitigation only Fix from $1,9502021-02-17 HIGH 8.0 CVE-2020-4955 IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter… Spectrum Protect Operations Center 7.1.13.000 / 8.1.10.200+ Fix from $1,9502021-02-15 CRITICAL 9.1 CVE-2021-21014 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful e… Magento 2.3.6+ Fix from $2,3002021-02-11 CRITICAL 9.8 CVE-2020-28871EPSS 86% Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure fi… Monitorr No fix yet Fix from $2,3002021-02-10 MEDIUM 6.5 CVE-2021-21131EPSS 8% Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions… Chrome 88.0.705.50 / 88.0.4324.96+ Fix from $1,6002021-02-09 CRITICAL 9.8 CVE-2021-26918 The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins th… Bot after 2021-02-08 Fix from $2,3002021-02-09 HIGH 8.2 CVE-2020-25037 UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command. Ucopia Wireless Appliance after 6.0.5 Fix from $1,9502021-02-02 CRITICAL 9.8 CVE-2021-3378EPSS 98% FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then… Fortilogger 5.2.0+ Fix from $2,3002021-02-01 CRITICAL 9.8 CVE-2020-20287 Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote cod… Yccms No fix yet Fix from $2,3002021-02-01 HIGH 8.8 CVE-2021-3164 ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and e… Churchrota No fix yet Fix from $1,9502021-01-26 HIGH 7.8 CVE-2021-22697 A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)… Ecostruxure Power Build Rapsody after 2.1.13 Fix from $1,9502021-01-26 HIGH 7.8 CVE-2021-22698 A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)… Ecostruxure Power Build Rapsody after 2.1.13 Fix from $1,9502021-01-26 HIGH 7.2 CVE-2020-22643 Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in… Feehi Cms No fix yet Fix from $1,9502021-01-26 HIGH 8.8 CVE-2020-24549 openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server. Openmaint 1.1-2.4.2+ Fix from $1,9502021-01-26 HIGH 7.2 CVE-2020-26285 OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remo… Openmage 19.4.10 / 20.0.5+ Fix from $1,9502021-01-21