Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 10.0
CVE-2024-52372

Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer allows Upload a Web Shell to …

Mitigation only
Fix from $2,300 2024-11-14
Unclassified CRITICAL 10.0
CVE-2024-52373

Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows Upload a Web Shell to a Web S…

Mitigation only
Fix from $2,300 2024-11-14
Unclassified HIGH 8.7
CVE-2024-52302

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a…

Patch available
Fix from $1,950 2024-11-14
Best Employee Management System HIGH 7.2
CVE-2024-11214

A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown c…

No fix yet
Fix from $1,950 2024-11-14
Eyoucms HIGH 7.2
CVE-2024-11211

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. …

Fix: after 1.6.7
Fix from $1,950 2024-11-14
Woocommerce Upload Files CRITICAL 9.8
CVE-2024-10820

The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() f…

Fix: 84.4+
Fix from $2,300 2024-11-13
Dedecms CRITICAL 9.8
CVE-2024-11138

A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_a…

Mitigation only
Fix from $2,300 2024-11-12
Lingdang Crm CRITICAL 9.8
CVE-2024-11122

A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is s…

Fix: after 8.6.4.3
Fix from $2,300 2024-11-12
Webopac CRITICAL 9.8
CVE-2024-11018

Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshell…

Fix: 6.5.1 / 7.2.3+
Fix from $2,300 2024-11-11
Webopac HIGH 8.8
CVE-2024-11017

Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute …

Fix: 6.5.1 / 7.2.3+
Fix from $1,950 2024-11-11
Unclassified CRITICAL 10.0
CVE-2024-51792

Unrestricted Upload of File with Dangerous Type vulnerability in Dang Ngoc Binh Audio Record audio-record allows Upload a Web Shell to a Web Server.T…

Mitigation only
Fix from $2,300 2024-11-11
Computer Repair Shop CRITICAL 9.8
CVE-2024-51793

Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Ser…

Fix: after 3.8115
Fix from $2,300 2024-11-11
Unclassified CRITICAL 10.0
CVE-2024-51789

Unrestricted Upload of File with Dangerous Type vulnerability in UjW0L Image Classify image-classify allows Upload a Web Shell to a Web Server.This i…

Mitigation only
Fix from $2,300 2024-11-11
Unclassified CRITICAL 10.0
CVE-2024-51790

Unrestricted Upload of File with Dangerous Type vulnerability in HB WEBSOL HB AUDIO GALLERY hb-audio-gallery allows Upload a Web Shell to a Web Serve…

Mitigation only
Fix from $2,300 2024-11-11
Unclassified CRITICAL 10.0
CVE-2024-51791

Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issu…

Mitigation only
Fix from $2,300 2024-11-11
Unclassified CRITICAL 10.0
CVE-2024-51788

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upl…

Mitigation only
Fix from $2,300 2024-11-11
Simple Music Cloud Community System CRITICAL 9.8
CVE-2024-11054

A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code o…

No fix yet
Fix from $2,300 2024-11-10
Unclassified CRITICAL 9.8
CVE-2024-10801

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_f…

Mitigation only
Fix from $2,300 2024-11-09
Unclassified CRITICAL 9.8
CVE-2024-10547

The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload()…

Mitigation only
Fix from $2,300 2024-11-09
Woocommerce Support Ticket System CRITICAL 9.8
CVE-2024-10627

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_ma…

Fix: 17.8+
Fix from $2,300 2024-11-09
Laravel Cms HIGH 7.2
CVE-2024-51152

File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.

Fix: after 1.4.7
Fix from $1,950 2024-11-08
Real Estate Management System HIGH 7.2
CVE-2024-11000

A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown func…

No fix yet
Fix from $1,950 2024-11-08
Real Estate Management System HIGH 7.2
CVE-2024-10999

A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file …

No fix yet
Fix from $1,950 2024-11-08
Online Institute Management System HIGH 8.8
CVE-2024-10993

A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of t…

No fix yet
Fix from $1,950 2024-11-08
Online Institute Management System HIGH 8.8
CVE-2024-10994

A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an un…

No fix yet
Fix from $1,950 2024-11-08
Quick Share HIGH 7.5
CVE-2024-10668

There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the vulnerability l…

Fix: 1.0.2002.2+
Fix from $1,950 2024-11-07
Jobsearch Wp Job Board HIGH 8.8
CVE-2024-8614

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handl…

Fix: 2.6.8+
Fix from $1,950 2024-11-06
Jobsearch Wp Job Board CRITICAL 9.8
CVE-2024-8615

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location…

Fix: 2.6.8+
Fix from $2,300 2024-11-06
Mfolio HIGH 8.8
CVE-2024-9307

The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. Thi…

Fix: after 1.2.1
Fix from $1,950 2024-11-06
Free Exam Hall Seating Management System CRITICAL 9.8
CVE-2024-10766

A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some u…

No fix yet
Fix from $2,300 2024-11-04