Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Online Notice Board CRITICAL 9.8
CVE-2024-12233

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of th…

No fix yet
Fix from $2,300 2024-12-05
Aspect Ent 12 Firmware HIGH 8.8
CVE-2024-51548

Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.…

Fix: 3.08.03+
Fix from $1,950 2024-12-05
Unclassified HIGH 8.7
CVE-2024-53982

ZOO-Project is a C-based WPS (Web Processing Service) implementation. A path traversal vulnerability was discovered in Zoo-Project Echo example. The …

Patch available
Fix from $1,950 2024-12-04
Convert Forms CRITICAL 9.8
CVE-2024-40744

Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.

Fix: 4.4.8+
Fix from $2,300 2024-12-04
Unclassified HIGH 8.8
CVE-2024-46625

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute…

Mitigation only
Fix from $1,950 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-25020

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Jou…

Mitigation only
Fix from $2,300 2024-12-03
Synapse CRITICAL 9.1
CVE-2024-53863

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially cra…

Fix: 1.120.1+
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-40691

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web …

Mitigation only
Fix from $2,300 2024-12-03
Cognos Controller CRITICAL 9.8
CVE-2024-25019

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry a…

Mitigation only
Fix from $2,300 2024-12-03
Advanced File Manager HIGH 7.5
CVE-2024-11391

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connect…

Fix: 5.2.11+
Fix from $1,950 2024-12-03
Freepbx HIGH 7.2
CVE-2024-53564

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege a…

Mitigation only
Fix from $1,950 2024-12-02
Unclassified CRITICAL 10.0
CVE-2024-52476

Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web …

Mitigation only
Fix from $2,300 2024-12-02
Unclassified CRITICAL 9.8
CVE-2024-11979

DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote at…

Mitigation only
Fix from $2,300 2024-11-29
Jpress MEDIUM 5.4
CVE-2024-11971

A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functiona…

No fix yet
Fix from $1,600 2024-11-28
Unclassified CRITICAL 10.0
CVE-2024-52490

Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web Shell to a Web Server.This i…

Mitigation only
Fix from $2,300 2024-11-28
Unclassified CRITICAL 9.9
CVE-2024-11082

The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_pan…

Patch available
Fix from $2,300 2024-11-28
Filester HIGH 8.8
CVE-2024-8066

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function …

Fix: 1.8.7+
Fix from $1,950 2024-11-28
Spip MEDIUM 6.3
CVE-2024-53619

An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading …

No fix yet
Fix from $1,600 2024-11-26
Unclassified HIGH 7.2
CVE-2024-9504

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio…

Mitigation only
Fix from $1,950 2024-11-26
Hospital Management System HIGH 8.8
CVE-2024-11674

A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file…

No fix yet
Fix from $1,950 2024-11-26
Free Exam Hall Seating Management System CRITICAL 9.8
CVE-2024-11661

A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic. This vulnerability affects u…

No fix yet
Fix from $2,300 2024-11-25
School Management System HIGH 8.8
CVE-2024-9660

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj…

Fix: 92.0.0+
Fix from $1,950 2024-11-23
Wordpress Gym Management System CRITICAL 9.8
CVE-2024-9942

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the M…

Fix: 67.2.0+
Fix from $2,300 2024-11-23
School Management System CRITICAL 9.8
CVE-2024-9659

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj…

Fix: 92.0.0+
Fix from $2,300 2024-11-23
Unclassified HIGH 8.8
CVE-2024-51364

An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.

No fix yet
Fix from $1,950 2024-11-21
Unclassified CRITICAL 9.8
CVE-2024-51366

An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a cr…

Mitigation only
Fix from $2,300 2024-11-21
Unclassified CRITICAL 10.0
CVE-2024-8525

An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execu…

Mitigation only
Fix from $2,300 2024-11-21
Hkcms CRITICAL 9.8
CVE-2024-52677

HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.

Fix: after 2.3.2.240702
Fix from $2,300 2024-11-20
Dedebiz HIGH 7.2
CVE-2024-52769

An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploa…

No fix yet
Fix from $1,950 2024-11-20
Boat Booking System HIGH 7.2
CVE-2024-51208

File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script…

Mitigation only
Fix from $1,950 2024-11-20