Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,274 CVEs tagged with CWE-4341,505 Critical, 1,641 High, 886 Medium, 241 Low, 1 Unrated.

CVE-2018-25019

Published Nov 1, 2021

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41646

Published Oct 29, 2021

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41644

Published Oct 29, 2021

Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41675

Published Oct 29, 2021

A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, which validates images with ge…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36548

Published Oct 28, 2021

A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-36547

Published Oct 28, 2021

A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-40344

Published Oct 26, 2021

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41178

Published Oct 25, 2021

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download ar…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39221

Published Oct 25, 2021

Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vul…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36485

Published Oct 22, 2021

Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-23043

Published Oct 22, 2021

Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42840

Published Oct 22, 2021

SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41745

Published Oct 22, 2021

ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-38471

Published Oct 22, 2021

There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-39352

Published Oct 21, 2021

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions u…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38346

Published Oct 14, 2021

The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-42342

Published Oct 14, 2021

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,276-3,300 of 4,274 CVEsPage 132 of 171