Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2020-26295 OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/… Openmage 19.4.10 / 20.0.5+ Fix from $1,9502021-01-21 HIGH 7.2 CVE-2020-26252 OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remo… Openmage 19.4.10 / 20.0.6+ Fix from $1,9502021-01-20 HIGH 8.8 CVE-2020-19364EPSS 71% OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. Openemr No fix yet Fix from $1,9502021-01-20 MEDIUM 6.5 CVE-2020-29450 Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Serv… Confluence Data Center 7.2.0+ Fix from $1,6002021-01-19 HIGH 7.5 CVE-2021-3166 An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when the filename… Dsl N14u B1 Firmware No fix yet Fix from $1,9502021-01-18 CRITICAL 9.8 CVE-2021-21245 OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputSt… Onedev 4.0.3+ Fix from $2,3002021-01-15 CRITICAL 9.8 CVE-2019-18643 Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanis… Rock Rms 8.10 / 9.4+ Fix from $2,3002021-01-07 HIGH 8.8 CVE-2020-36167 An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it … Backup Exec 20.0.1188.2734 / 21.0.1200.1217+ Fix from $1,9502021-01-06 MEDIUM 6.7 CVE-2020-4928 IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extent… Cloud Pak System 2.3.3.3+ Fix from $1,6002021-01-04 HIGH 8.8 CVE-2020-35945 An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contri… Divi 4.5.3+ Fix from $1,9502021-01-01 CRITICAL 9.8 CVE-2020-35949 An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload … Quiz And Survey Master 7.0.1+ Fix from $2,3002021-01-01 CRITICAL 9.8 CVE-2020-35797 NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker. Nms300 Firmware 1.6.0.27+ Fix from $2,3002020-12-30 HIGH 7.5 CVE-2020-26286 HedgeDoc is a collaborative platform for writing and sharing markdown. In HedgeDoc before version 1.7.1 an unauthenticated attacker can upload arbitr… Hedgedoc 1.7.1+ Fix from $1,9502020-12-29 HIGH 8.8 CVE-2020-35627 Ultimate WooCommerce Gift Cards 3.0.2 is affected by a file upload vulnerability in the Custom GiftCard Template that can remotely execute arbitrary … Gift Cards No fix yet Fix from $1,9502020-12-28 HIGH 8.8 CVE-2020-27397 Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain rem… Online Matrimonial Project No fix yet Fix from $1,9502020-12-23 HIGH 7.2 CVE-2020-35657 Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive … Jaws after 1.8.0 Fix from $1,9502020-12-23 HIGH 7.2 CVE-2020-35656 Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=I… Jaws after 1.8.0 Fix from $1,9502020-12-23 HIGH 8.8 CVE-2020-26174 tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this … Business Workflow 1.18.1+ Fix from $1,9502020-12-18 CRITICAL 10.0 CVE-2020-35489EPSS 89% The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filenam… Contact Form 7 5.3.2+ Fix from $2,3002020-12-17 CRITICAL 9.8 CVE-2020-25010 An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 all… Kps2204 6 Port Managed Din Rail Programmable Serial Device Firmware Mitigation only Fix from $2,3002020-12-17 HIGH 7.5 CVE-2020-35133 irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60. Irfanview No fix yet Fix from $1,9502020-12-16 HIGH 7.2 CVE-2020-29607EPSS 33% A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "man… Pluck 4.7.13+ Fix from $1,9502020-12-16 HIGH 7.2 CVE-2020-28072 A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in t… Alumni Management System No fix yet Fix from $1,9502020-12-15 MEDIUM 6.5 CVE-2020-26826 Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) … Netweaver Application Server Java Mitigation only Fix from $1,6002020-12-09 MEDIUM 6.4 CVE-2020-26828 SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some f… Disclosure Management Mitigation only Fix from $1,6002020-12-09 HIGH 7.2 CVE-2020-23520 imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality. Imcat No fix yet Fix from $1,9502020-12-09 CRITICAL 9.1 CVE-2020-26255 Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Pan… Kirby 2.5.14 / 3.4.5+ Fix from $2,3002020-12-08 CRITICAL 9.8 CVE-2020-29597EPSS 71% IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to up… Incomcms No fix yet Fix from $2,3002020-12-07 HIGH 7.2 CVE-2020-28939 OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (wit… Openclinic No fix yet Fix from $1,9502020-12-03 MEDIUM 6.5 CVE-2020-29441 An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In… Outsystems 10.0.1019.0+ Fix from $1,6002020-11-30