Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,266 CVEs tagged with CWE-4341,504 Critical, 1,635 High, 885 Medium, 240 Low, 2 Unrated.

CVE-2021-25780

Published Feb 17, 2021

An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to th…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4955

Published Feb 15, 2021

IBM Spectrum Protect Operations Center 7.1 and 8.1could allow a remote attacker to execute arbitrary code on the system, caused by improper parameter validation. By creating an un…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21014

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28871

Published Feb 10, 2021

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-26918

Published Feb 9, 2021

The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3378

Published Feb 1, 2021

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-20287

Published Feb 1, 2021

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3164

Published Jan 26, 2021

ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to upload and execute an arbitrary file via a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24549

Published Jan 26, 2021

openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-22643

Published Jan 26, 2021

Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26295

Published Jan 21, 2021

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrator with permission to import/export data and to edit cms pa…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26285

Published Jan 21, 2021

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vulnerability which enables remote code execution. In affected…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26252

Published Jan 20, 2021

OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vulnerability which enables remote code execution. In affected…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-19364

Published Jan 20, 2021

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21245

Published Jan 15, 2021

OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified l…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18643

Published Jan 7, 2021

Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklis…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36167

Published Jan 6, 2021

An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4928

Published Jan 4, 2021

IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execut…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,501-3,525 of 4,266 CVEsPage 141 of 171