Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2020-26295
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/…
Openmage
19.4.10 / 20.0.5+
HIGH 7.2
CVE-2020-26252
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remo…
Openmage
19.4.10 / 20.0.6+
HIGH 8.8
CVE-2020-19364EPSS 71%
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
Openemr
No fix yet
MEDIUM 6.5
CVE-2020-29450
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Serv…
Confluence Data Center
7.2.0+
HIGH 7.5
CVE-2021-3166
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename…
Dsl N14u B1 Firmware
No fix yet
CRITICAL 9.8
CVE-2021-21245
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputSt…
Onedev
4.0.3+
CRITICAL 9.8
CVE-2019-18643
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanis…
Rock Rms
8.10 / 9.4+
HIGH 8.8
CVE-2020-36167
An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it …
Backup Exec
20.0.1188.2734 / 21.0.1200.1217+
MEDIUM 6.7
CVE-2020-4928
IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extent…
Cloud Pak System
2.3.3.3+
HIGH 8.8
CVE-2020-35945
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contri…
Divi
4.5.3+
CRITICAL 9.8
CVE-2020-35949
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload …
Quiz And Survey Master
7.0.1+
CRITICAL 9.8
CVE-2020-35797
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.
Nms300 Firmware
1.6.0.27+
HIGH 7.5
CVE-2020-26286
HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitr…
Hedgedoc
1.7.1+
HIGH 8.8
CVE-2020-35627
Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary …
Gift Cards
No fix yet
HIGH 8.8
CVE-2020-27397
Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain rem…
Online Matrimonial Project
No fix yet
HIGH 7.2
CVE-2020-35657
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive …
Jaws
after 1.8.0
HIGH 7.2
CVE-2020-35656
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=I…
Jaws
after 1.8.0
HIGH 8.8
CVE-2020-26174
tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this …
Business Workflow
1.18.1+
CRITICAL 10.0
CVE-2020-35489EPSS 89%
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filenam…
Contact Form 7
5.3.2+
CRITICAL 9.8
CVE-2020-25010
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 all…
Kps2204 6 Port Managed Din Rail Programmable Serial Device Firmware
Mitigation only
HIGH 7.5
CVE-2020-35133
irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.
Irfanview
No fix yet
HIGH 7.2
CVE-2020-29607EPSS 33%
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "man…
Pluck
4.7.13+
HIGH 7.2
CVE-2020-28072
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in t…
Alumni Management System
No fix yet
MEDIUM 6.5
CVE-2020-26826
Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) …
Netweaver Application Server Java
Mitigation only
MEDIUM 6.4
CVE-2020-26828
SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some f…
Disclosure Management
Mitigation only
HIGH 7.2
CVE-2020-23520
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.
Imcat
No fix yet
CRITICAL 9.1
CVE-2020-26255
Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Pan…
Kirby
2.5.14 / 3.4.5+
CRITICAL 9.8
CVE-2020-29597EPSS 71%
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to up…
Incomcms
No fix yet
HIGH 7.2
CVE-2020-28939
OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (wit…
Openclinic
No fix yet
MEDIUM 6.5
CVE-2020-29441
An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In…
Outsystems
10.0.1019.0+