Total
3136 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-46116 | 1 Jpress | 1 Jpress | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code. | |||||
CVE-2021-46115 | 1 Jpress | 1 Jpress | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code. | |||||
CVE-2021-46113 | 1 Kea-hotel-erp Project | 1 Kea-hotel-erp | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service. | |||||
CVE-2021-46097 | 1 Dolphinphp | 1 Dolphinphp | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log | |||||
CVE-2021-46079 | 1 Vehicle Service Management System Project | 1 Vehicle Service Management System | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection. | |||||
CVE-2021-46078 | 1 Vehicle Service Management System Project | 1 Vehicle Service Management System | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to a Stored Cross-Site Scripting vulnerability. | |||||
CVE-2021-46076 | 1 Vehicle Service Management System Project | 1 Vehicle Service Management System | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution. | |||||
CVE-2021-46036 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code. | |||||
CVE-2021-46033 | 1 Forestblog Project | 1 Forestblog | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
In ForestBlog, as of 2021-12-28, File upload can bypass verification. | |||||
CVE-2021-46013 | 1 Free School Management Software Project | 1 Free School Management Software | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users. | |||||
CVE-2021-45982 | 1 Netscout | 1 Ngeniusone | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. | |||||
CVE-2021-45865 | 1 Student Attendance Management System Project | 1 Student Attendance Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality. | |||||
CVE-2021-45835 | 1 Online Admission System Project | 1 Online Admissions System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution. | |||||
CVE-2021-45834 | 1 Opendocman | 1 Opendocman | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution. | |||||
CVE-2021-45808 | 1 Jpress | 1 Jpress | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server. | |||||
CVE-2021-45790 | 1 Metersphere | 1 Metersphere | 2024-11-21 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands. | |||||
CVE-2021-45411 | 1 Printable Staff Id Card Creator System Project | 1 Printable Staff Id Card Creator System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution. | |||||
CVE-2021-45040 | 1 Spatie | 1 Laravel Media Library | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route. | |||||
CVE-2021-44673 | 1 Croogo | 1 Croogo | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script. | |||||
CVE-2021-44664 | 1 Xerte | 1 Xerte | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable. |