Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Portfolio Management System Mca CRITICAL 9.8
CVE-2024-12954

A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. This affects an unknown part of th…

No fix yet
Fix from $2,300 2024-12-26
Portfolio Management System Mca CRITICAL 9.8
CVE-2024-12953

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected by this issue is som…

No fix yet
Fix from $2,300 2024-12-26
Portfolio Management System Mca CRITICAL 9.8
CVE-2024-12951

A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the fi…

No fix yet
Fix from $2,300 2024-12-26
Magicos HIGH 7.8
CVE-2024-47151

Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution

Fix: 8.0.0.135+
Fix from $1,950 2024-12-26
Directorypress MEDIUM 5.4
CVE-2024-10584

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo…

Fix: 3.6.17+
Fix from $1,600 2024-12-24
Cognos Analytics HIGH 8.0
CVE-2024-40695

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the cont…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2024-12-20
Unclassified HIGH 8.8
CVE-2024-12700

There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute…

Mitigation only
Fix from $1,950 2024-12-19
Unclassified HIGH 8.8
CVE-2024-11984

A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows …

Mitigation only
Fix from $1,950 2024-12-19
Wordpress Learning Management System HIGH 8.8
CVE-2024-56054

Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a…

Fix: 1.9.9.5.2+
Fix from $1,950 2024-12-18
Wordpress Learning Management System HIGH 8.8
CVE-2024-56057

Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a…

Fix: 1.9.9.5.2+
Fix from $1,950 2024-12-18
Wordpress Learning Management System HIGH 8.8
CVE-2024-56050

Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a…

Fix: 1.9.9.5.3+
Fix from $1,950 2024-12-18
Wordpress Learning Management System HIGH 8.8
CVE-2024-56052

Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a…

Fix: 1.9.9.5.2+
Fix from $1,950 2024-12-18
Msg2300 Firmware MEDIUM 6.3
CVE-2024-55514

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the …

Mitigation only
Fix from $1,600 2024-12-17
Unclassified CRITICAL 9.1
CVE-2024-54285

Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affec…

Mitigation only
Fix from $2,300 2024-12-16
Unclassified CRITICAL 9.9
CVE-2024-54370

Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member a…

Mitigation only
Fix from $2,300 2024-12-16
Invoiceplane HIGH 8.8
CVE-2024-12478

A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the f…

Fix: after 1.6.1
Fix from $1,950 2024-12-16
Unclassified HIGH 7.2
CVE-2024-9698

The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_…

Mitigation only
Fix from $1,950 2024-12-14
Unclassified CRITICAL 9.9
CVE-2024-54262

Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a W…

Mitigation only
Fix from $2,300 2024-12-13
Unclassified CRITICAL 9.8
CVE-2024-9290

The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and…

Mitigation only
Fix from $2,300 2024-12-13
Mstore Api MEDIUM 5.4
CVE-2024-12042

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile pict…

Fix: 4.16.5+
Fix from $1,600 2024-12-13
Unclassified HIGH 8.8
CVE-2024-10590

The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_upload() function …

Mitigation only
Fix from $1,950 2024-12-12
macOS MEDIUM 5.5
CVE-2024-44220

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted …

Fix: 14.7.2 / 15.2+
Fix from $1,600 2024-12-12
Struts CRITICAL 9.8
CVE-2024-53677EPSS 78%

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances th…

Fix: 6.4.0+
Fix from $2,300 2024-12-11
Unclassified HIGH 7.2
CVE-2024-47946

If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PH…

Mitigation only
Fix from $1,950 2024-12-10
Connectport Lts Firmware HIGH 8.0
CVE-2024-50625

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation o…

Fix: 1.4.12+
Fix from $1,950 2024-12-09
E Learning Management System CRITICAL 9.8
CVE-2024-54918

Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.

No fix yet
Fix from $2,300 2024-12-09
Unclassified CRITICAL 10.0
CVE-2024-53822

Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a befo…

Mitigation only
Fix from $2,300 2024-12-09
Unclassified CRITICAL 10.0
CVE-2024-54214

Unrestricted Upload of File with Dangerous Type vulnerability in roninwp Revy revy allows Upload a Web Shell to a Web Server.This issue affects Revy:…

Mitigation only
Fix from $2,300 2024-12-06
Unclassified MEDIUM 6.6
CVE-2024-53811

Unrestricted Upload of File with Dangerous Type vulnerability in POSIMYTH WDesignkit wdesignkit allows Upload a Web Shell to a Web Server.This issue …

Mitigation only
Fix from $1,600 2024-12-06
Unclassified HIGH 8.8
CVE-2024-10578

The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer…

Mitigation only
Fix from $1,950 2024-12-06