Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2021-24145EPSS 88%
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing…
Modern Events Calendar Lite
5.16.5+
HIGH 7.2
CVE-2021-24123
Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones fr…
Powerpress
8.3.8+
CRITICAL 9.8
CVE-2021-28294
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code…
Online Ordering System
No fix yet
CRITICAL 9.8
CVE-2021-27817
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which…
Shopxo
Mitigation only
HIGH 8.8
CVE-2021-28379EPSS 6%
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different or…
Myvesta
after 0.9.8-27
HIGH 7.2
CVE-2020-29032
Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious co…
Gatemanager 8250 Firmware
9.4.621054022+
CRITICAL 9.8
CVE-2021-27964EPSS 48%
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFi…
Sonlogger
6.4.1+
HIGH 7.2
CVE-2020-36079
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the upload…
Zenphoto
after 1.5.7
CRITICAL 9.8
CVE-2021-27198EPSS 14%
An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in…
Myconnection Server
11.1a+
HIGH 8.8
CVE-2021-20659
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PH…
Sv Cpt Mc310 Firmware
6.5+
HIGH 8.0
CVE-2020-7847
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote co…
Nas I Firmware
1.4.36+
CRITICAL 9.8
CVE-2021-3120EPSS 37%
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achiev…
Yith Woocommerce Gift Cards
3.3.1+
HIGH 8.8
CVE-2021-27513EPSS 28%
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre us…
Eyesofnetwork
Patch available
HIGH 7.2
CVE-2021-25780
An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote at…
Baby Care System
No fix yet
CRITICAL 9.8
CVE-2021-26809
PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
Car Rental Portal
No fix yet
HIGH 8.8
CVE-2021-22858
Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrary commands or files after obt…
Changjia Property Management System
Mitigation only
HIGH 8.0
CVE-2020-4955
IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter…
Spectrum Protect Operations Center
7.1.13.000 / 8.1.10.200+
CRITICAL 9.1
CVE-2021-21014
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful e…
Magento
2.3.6+
CRITICAL 9.8
CVE-2020-28871EPSS 86%
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure fi…
Monitorr
No fix yet
MEDIUM 6.5
CVE-2021-21131EPSS 8%
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions…
Chrome
88.0.705.50 / 88.0.4324.96+
CRITICAL 9.8
CVE-2021-26918
The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins th…
Bot
after 2021-02-08
HIGH 8.2
CVE-2020-25037
UCOPIA Wi-Fi appliances 6.0.5 allow arbitrary code execution with admin user privileges via an escape from a restricted command.
Ucopia Wireless Appliance
after 6.0.5
CRITICAL 9.8
CVE-2021-3378EPSS 98%
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then…
Fortilogger
5.2.0+
CRITICAL 9.8
CVE-2020-20287
Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote cod…
Yccms
No fix yet
HIGH 8.8
CVE-2021-3164
ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and e…
Churchrota
No fix yet
HIGH 7.8
CVE-2021-22697
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)…
Ecostruxure Power Build Rapsody
after 2.1.13
HIGH 7.8
CVE-2021-22698
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior)…
Ecostruxure Power Build Rapsody
after 2.1.13
HIGH 7.2
CVE-2020-22643
Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in…
Feehi Cms
No fix yet
HIGH 8.8
CVE-2020-24549
openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
Openmaint
1.1-2.4.2+
HIGH 7.2
CVE-2020-26285
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remo…
Openmage
19.4.10 / 20.0.5+