Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Trudesk HIGH 8.0
CVE-2022-1752

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

Fix: 1.2.2+
Fix from $1,950 2022-05-21
Pharmacy Management System CRITICAL 9.8
CVE-2022-30887EPSS 26%

Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.…

No fix yet
Fix from $2,300 2022-05-20
Pdf Editor CRITICAL 9.8
CVE-2022-28104

Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.

No fix yet
Fix from $2,300 2022-05-20
Subconverter CRITICAL 9.8
CVE-2022-28927EPSS 34%

A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters.

Patch available
Fix from $2,300 2022-05-19
Shopxo HIGH 7.2
CVE-2021-41938

An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.

No fix yet
Fix from $1,950 2022-05-19
Sterling B2b Integrator MEDIUM 6.5
CVE-2022-22482

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files th…

Fix: after 6.1.1.0
Fix from $1,600 2022-05-17
Gxcms HIGH 7.2
CVE-2022-30007

GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content an…

No fix yet
Fix from $1,950 2022-05-17
Hotel Booking Engine \& Pms HIGH 7.2
CVE-2022-1409

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as admi…

Fix: 1.5.8+
Fix from $1,950 2022-05-16
Automatic Grid Image Listing HIGH 7.2
CVE-2021-25119

The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allow…

Fix: after 1.0
Fix from $1,950 2022-05-16
Advanced Uploader HIGH 8.8
CVE-2022-1103EPSS 16%

The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could…

Fix: after 4.2
Fix from $1,950 2022-05-16
Formidable CRITICAL 9.8
CVE-2022-29622

An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parti…

No fix yet
Fix from $2,300 2022-05-16
Connect Multiparty HIGH 7.8
CVE-2022-29623

An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a…

No fix yet
Fix from $1,950 2022-05-16
Tiddlywiki5 CRITICAL 9.8
CVE-2022-29351

An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG f…

Mitigation only
Fix from $2,300 2022-05-16
Graphql Upload CRITICAL 9.8
CVE-2022-29353

An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted f…

No fix yet
Fix from $2,300 2022-05-16
Keystone CRITICAL 9.8
CVE-2022-29354

An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $2,300 2022-05-16
Mypro HIGH 7.5
CVE-2021-33009

mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.

Fix: 8.20.0+
Fix from $1,950 2022-05-13
Novel Plus CRITICAL 9.8
CVE-2021-42967

Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an …

No fix yet
Fix from $2,300 2022-05-13
Sametime HIGH 7.6
CVE-2021-27771

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal m…

Mitigation only
Fix from $1,950 2022-05-12
Inrouter302 Firmware HIGH 8.1
CVE-2022-21809

A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can l…

Fix: after 3.5.37
Fix from $1,950 2022-05-12
Hospital Management System CRITICAL 9.8
CVE-2022-30448

Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.

No fix yet
Fix from $2,300 2022-05-11
Car Rental Management System HIGH 7.2
CVE-2022-29318

An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a …

No fix yet
Fix from $1,950 2022-05-11
Wedding Management System HIGH 7.2
CVE-2022-29655

An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a…

No fix yet
Fix from $1,950 2022-05-11
Bludit HIGH 7.2
CVE-2020-19228

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

No fix yet
Fix from $1,950 2022-05-11
Cmsimple Xh CRITICAL 10.0
CVE-2021-42645

CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" paramete…

Mitigation only
Fix from $2,300 2022-05-10
Open Virtual Simulation Experiment Teaching Management Platform CRITICAL 9.8
CVE-2022-28120

Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerabil…

No fix yet
Fix from $2,300 2022-05-05
Bosscms CRITICAL 9.8
CVE-2022-28606

An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker t…

Mitigation only
Fix from $2,300 2022-05-05
Yetiforce Customer Relationship Management MEDIUM 6.1
CVE-2022-1411

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able …

Fix: 6.4.0+
Fix from $1,600 2022-05-05
Simple Doctor\'s Appointment System CRITICAL 9.8
CVE-2022-28568

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obt…

Mitigation only
Fix from $2,300 2022-05-04
Web\@rchiv CRITICAL 9.8
CVE-2022-29347

An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

Mitigation only
Fix from $2,300 2022-05-04
Springbootmovie HIGH 7.2
CVE-2022-29001

In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability

Fix: after 1.2
Fix from $1,950 2022-05-03