Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-434 Clear
ID Title
CVE-2017-12615 KEV [KEV] Unrestricted File Upload in Apache tomcat (CVE-2017-12615)
vulnerability in Apache tomcat (CVE-2017-12615). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2022-23346 BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
CVE-2021-45834 Unrestricted File Upload in opendocman (CVE-2021-45834)
vulnerability in opendocman (CVE-2021-45834). Successful exploitation can lead to full system takeover.
CVE-2022-24251 Unrestricted File Upload in extensis (CVE-2022-24251)
vulnerability in extensis (CVE-2022-24251). Successful exploitation can lead to full system takeover.
CVE-2022-24254 Unrestricted File Upload in extensis (CVE-2022-24254)
vulnerability in extensis (CVE-2022-24254). Successful exploitation can lead to full system takeover.
CVE-2022-24252 Unrestricted File Upload in extensis (CVE-2022-24252)
vulnerability in extensis (CVE-2022-24252). Successful exploitation can lead to full system takeover.
CVE-2022-24253 Unrestricted File Upload in extensis (CVE-2022-24253)
vulnerability in extensis (CVE-2022-24253). Successful exploitation can lead to full system takeover.
CVE-2021-46116 Unrestricted File Upload in jpress (CVE-2021-46116)
vulnerability in jpress (CVE-2021-46116). Successful exploitation can lead to full system takeover.
CVE-2021-46115 Unrestricted File Upload in c (CVE-2021-46115)
vulnerability in c (CVE-2021-46115). Successful exploitation can lead to full system takeover.
CVE-2021-45808 Unrestricted File Upload in jpress (CVE-2021-45808)
vulnerability in jpress (CVE-2021-45808). Successful exploitation can lead to full system takeover.
CVE-2020-13671 KEV [KEV] Unrestricted File Upload in drupal (CVE-2020-13671)
vulnerability in drupal (CVE-2020-13671). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2021-27860 KEV [KEV] Unrestricted File Upload in Fatpipe warp (CVE-2021-27860)
vulnerability in Fatpipe warp (CVE-2021-27860). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2018-15961 KEV [KEV] Unrestricted File Upload in Adobe coldfusion (CVE-2018-15961)
vulnerability in Adobe coldfusion (CVE-2018-15961). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-31207 KEV [KEV] Vulnerability in Microsoft exchange-server (CVE-2021-31207)
vulnerability in Microsoft exchange-server (CVE-2021-31207). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-8260 KEV [KEV] Unrestricted File Upload in Ivanti pulse-connect-secure (CVE-2020-8260)
vulnerability in Ivanti pulse-connect-secure (CVE-2020-8260). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-20022 KEV [KEV] Unrestricted File Upload in Sonicwall email-security (CVE-2021-20022)
vulnerability in Sonicwall email-security (CVE-2021-20022). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-25213 KEV [KEV] Unrestricted File Upload in Wordpress file-manager-plugin (CVE-2020-25213)
vulnerability in Wordpress file-manager-plugin (CVE-2020-25213). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-8394 KEV [KEV] Unrestricted File Upload in Zoho manageengine (CVE-2019-8394)
vulnerability in Zoho manageengine (CVE-2019-8394). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2020-3436 Unrestricted File Upload in dos (CVE-2020-3436)
vulnerability in dos (CVE-2020-3436). Risk of unauthorized operations or information disclosure.
CVE-2020-1112 Unrestricted File Upload in microsoft (CVE-2020-1112)
vulnerability in microsoft (CVE-2020-1112). Successful exploitation can lead to full system takeover.
CVE-2020-1102 Unrestricted File Upload in microsoft (CVE-2020-1102)
vulnerability in microsoft (CVE-2020-1102). Successful exploitation can lead to full system takeover.
CVE-2020-1023 Unrestricted File Upload in microsoft (CVE-2020-1023)
vulnerability in microsoft (CVE-2020-1023). Successful exploitation can lead to full system takeover.
CVE-2020-1024 Unrestricted File Upload in microsoft (CVE-2020-1024)
vulnerability in microsoft (CVE-2020-1024). Successful exploitation can lead to full system takeover.
CVE-2019-19634 Unrestricted File Upload in verot/class.upload.php (CVE-2019-19634)
vulnerability in verot/class.upload.php (CVE-2019-19634). Successful exploitation can lead to full system takeover.
CVE-2019-19576 Unrestricted File Upload in verot/class.upload.php (CVE-2019-19576)
vulnerability in verot/class.upload.php (CVE-2019-19576). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.4` or later.
CVE-2018-9206 Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
CVE-2017-17987 Unrestricted File Upload in muslim-matrimonial-script-project (CVE-2017-17987)
vulnerability in muslim-matrimonial-script-project (CVE-2017-17987). Successful exploitation can lead to full system takeover.
CVE-2017-17874 Unrestricted File Upload in vanguard-project (CVE-2017-17874)
vulnerability in vanguard-project (CVE-2017-17874). Successful exploitation can lead to full system takeover.
CVE-2017-15876 Unrestricted File Upload in sistemagpweb (CVE-2017-15876)
vulnerability in sistemagpweb (CVE-2017-15876). Successful exploitation can lead to full system takeover.
CVE-2017-16949 Unrestricted File Upload in wordpress (CVE-2017-16949)
vulnerability in wordpress (CVE-2017-16949). Successful exploitation can lead to full system takeover.
CVE-2017-17727 Unrestricted File Upload in dedecms (CVE-2017-17727)
vulnerability in dedecms (CVE-2017-17727). Successful exploitation can lead to full system takeover.
CVE-2017-17593 Unrestricted File Upload in simple-chatting-system-project (CVE-2017-17593)
vulnerability in simple-chatting-system-project (CVE-2017-17593). Data can be tampered with by attackers.
CVE-2017-13156 Unrestricted File Upload in google (CVE-2017-13156)
vulnerability in google (CVE-2017-13156). Successful exploitation can lead to full system takeover.
CVE-2017-12332 Unrestricted File Upload in cisco (CVE-2017-12332)
vulnerability in cisco (CVE-2017-12332). Data can be tampered with by attackers.
CVE-2017-15673 Unrestricted File Upload in cs-cart (CVE-2017-15673)
vulnerability in cs-cart (CVE-2017-15673). Successful exploitation can lead to full system takeover.
CVE-2017-15054 Unrestricted File Upload in teampass (CVE-2017-15054)
vulnerability in teampass (CVE-2017-15054). Successful exploitation can lead to full system takeover.
CVE-2017-16941 Unrestricted File Upload in octobercms (CVE-2017-16941)
vulnerability in octobercms (CVE-2017-16941). Successful exploitation can lead to full system takeover.
CVE-2017-2737 Unrestricted File Upload in huawei (CVE-2017-2737)
vulnerability in huawei (CVE-2017-2737). Successful exploitation can lead to full system takeover.
CVE-2017-2699 Unrestricted File Upload in huawei (CVE-2017-2699)
vulnerability in huawei (CVE-2017-2699). Successful exploitation can lead to full system takeover.
CVE-2017-8862 Unrestricted File Upload in cohuhd (CVE-2017-8862)
vulnerability in cohuhd (CVE-2017-8862). Successful exploitation can lead to full system takeover.
CVE-2017-1000238 Unrestricted File Upload in invoiceplane (CVE-2017-1000238)
vulnerability in invoiceplane (CVE-2017-1000238). Successful exploitation can lead to full system takeover.
CVE-2017-1000194 Unrestricted File Upload in apache (CVE-2017-1000194)
vulnerability in apache (CVE-2017-1000194). Successful exploitation can lead to full system takeover.
CVE-2017-16524 Unrestricted File Upload in hanwhasecurity (CVE-2017-16524)
vulnerability in hanwhasecurity (CVE-2017-16524). Successful exploitation can lead to full system takeover.
CVE-2017-10940 Path Traversal in joyent (CVE-2017-10940)
path traversal in joyent (CVE-2017-10940). Successful exploitation can lead to full system takeover.
CVE-2017-15990 Unrestricted File Upload in savsofteproducts (CVE-2017-15990)
vulnerability in savsofteproducts (CVE-2017-15990). Successful exploitation can lead to full system takeover.
CVE-2017-15957 Unrestricted File Upload in ingenious-school-management-system-project (CVE-2017-15957)
vulnerability in ingenious-school-management-system-project (CVE-2017-15957). Successful exploitation can lead to full system takeover.
CVE-2017-15962 iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
CVE-2011-4334 Unrestricted File Upload in labwiki-project (CVE-2011-4334)
vulnerability in labwiki-project (CVE-2011-4334). Successful exploitation can lead to full system takeover.
CVE-2017-15580 Unrestricted File Upload in osticket (CVE-2017-15580)
vulnerability in osticket (CVE-2017-15580). Successful exploitation can lead to full system takeover.
CVE-2014-2664 Unrestricted File Upload in x2engine (CVE-2014-2664)
vulnerability in x2engine (CVE-2014-2664). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →