Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,206 CVEs tagged with CWE-4341,480 Critical, 1,614 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2021-37444

Published Jul 25, 2021

NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathnam…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25203

Published Jul 23, 2021

Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-34619

Published Jul 21, 2021

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-35963

Published Jul 19, 2021

The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files cont…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29699

Published Jul 15, 2021

IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID:…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36121

Published Jul 13, 2021

An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm is susceptible to an unrestricted upload vulnerability via…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30118

Published Jul 9, 2021

An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files t…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-28931

Published Jul 7, 2021

Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a crafted zip file uploaded to the Themes…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32538

Published Jul 7, 2021

ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further ex…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-34624

Published Jul 7, 2021

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34623

Published Jul 7, 2021

A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitra…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-22249

Published Jul 6, 2021

Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-20104

Published Jun 29, 2021

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34074

Published Jun 25, 2021

PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-21786

Published Jun 24, 2021

In IBOS 4.5.4 Open, Arbitrary File Inclusion causes getshell via /system/modules/dashboard/controllers/CronController.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-21787

Published Jun 24, 2021

CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1433

Published Jun 21, 2021

Joomla! Core is prone to a vulnerability that lets attackers upload arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-24376

Published Jun 21, 2021

The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archive via the "Import Settings" feature, after its extraction.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,326-3,350 of 4,206 CVEsPage 134 of 169