Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,207 CVEs tagged with CWE-4341,481 Critical, 1,614 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2020-27461

Published Aug 20, 2021

A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-18886

Published Aug 20, 2021

Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-18879

Published Aug 20, 2021

Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-37608

Published Aug 18, 2021

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands. This issue affects Apache OFBiz version 17.12.07 and p…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-18704

Published Aug 16, 2021

Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29377

Published Aug 12, 2021

Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-38366

Published Aug 12, 2021

Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and achieve remote code execution by visiting an uploaded .aspx f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-18462

Published Aug 12, 2021

File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-20979

Published Aug 12, 2021

An arbitrary file upload vulnerability in the move_uploaded_file() function of LJCMS v4.3 allows attackers to execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28165

Published Aug 12, 2021

The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPac…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-21359

Published Aug 11, 2021

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-21976

Published Aug 11, 2021

An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38305

Published Aug 9, 2021

23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24499

Published Aug 9, 2021

The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-28088

Published Aug 6, 2021

An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-34639

Published Aug 5, 2021

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is exe…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2021-32594

Published Aug 4, 2021

An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow a low-…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19303

Published Aug 3, 2021

An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-19302

Published Aug 3, 2021

An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,301-3,325 of 4,207 CVEsPage 133 of 169