Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Online Institute Management System CRITICAL 9.8
CVE-2024-10764

A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /p…

No fix yet
Fix from $2,300 2024-11-04
Online Institute Management System CRITICAL 9.8
CVE-2024-10765

A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of…

No fix yet
Fix from $2,300 2024-11-04
Rsvpmaker CRITICAL 9.8
CVE-2024-50531

Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web…

Fix: 6.2.5+
Fix from $2,300 2024-11-04
Multi Purpose Mail Form CRITICAL 9.8
CVE-2024-50526

Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a We…

Fix: after 1.0.2
Fix from $2,300 2024-11-04
Stacks Mobile App Builder CRITICAL 9.8
CVE-2024-50527

Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell…

Fix: after 5.2.3
Fix from $2,300 2024-11-04
Training Courses HIGH 8.8
CVE-2024-50529

Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a Web Shell to a Web Server.This …

Fix: after 2.0.1
Fix from $1,950 2024-11-04
Stars Smtp Mailer HIGH 8.8
CVE-2024-50530

Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Upload a Web Shell to a …

Fix: after 1.7
Fix from $1,950 2024-11-04
All Post Contact Form CRITICAL 9.8
CVE-2024-50523

Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactform allows Upload a Web Shell…

Fix: after 1.7.3
Fix from $2,300 2024-11-04
Helloprint CRITICAL 9.8
CVE-2024-50525

Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Shell to a Web Server.This issu…

Fix: after 2.0.2
Fix from $2,300 2024-11-04
Elfinder CRITICAL 9.8
CVE-2023-52044

Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

No fix yet
Fix from $2,300 2024-10-31
Unclassified CRITICAL 9.8
CVE-2024-10392EPSS 15%

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_…

Mitigation only
Fix from $2,300 2024-10-31
Unclassified HIGH 8.0
CVE-2024-48093

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and exec…

Mitigation only
Fix from $1,950 2024-10-30
Unclassified HIGH 8.8
CVE-2024-48734

Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious file…

Mitigation only
Fix from $1,950 2024-10-30
Icecms CRITICAL 9.8
CVE-2024-48202

icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

Fix: after 3.4.7
Fix from $2,300 2024-10-30
Sage Frp 1000 HIGH 8.1
CVE-2024-48646

An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An att…

No fix yet
Fix from $1,950 2024-10-30
Unclassified CRITICAL 10.0
CVE-2024-50510

Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allows Upload a Web Shell to a Web…

Mitigation only
Fix from $2,300 2024-10-30
Unclassified CRITICAL 9.9
CVE-2024-50511

Unrestricted Upload of File with Dangerous Type vulnerability in donimedia WP donimedia carousel wp-donimedia-carousel allows Upload a Web Shell to a…

Mitigation only
Fix from $2,300 2024-10-30
Fileorganizer HIGH 8.8
CVE-2024-7985

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati…

Fix: after 1.0.9
Fix from $1,950 2024-10-29
Unclassified CRITICAL 10.0
CVE-2024-50420

Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Shell to a Web Server.This issu…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.9
CVE-2024-50427

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 10.0
CVE-2024-50473

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 10.0
CVE-2024-50482

Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Upload a Web She…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 10.0
CVE-2024-50484

Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a We…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 10.0
CVE-2024-50493

Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 10.0
CVE-2024-50494

Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-sudan-payment-gateway allows Uplo…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.9
CVE-2024-50480

Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows Upload a We…

Mitigation only
Fix from $2,300 2024-10-29
Ar CRITICAL 10.0
CVE-2024-50496

Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Ser…

Fix: after 7.0
Fix from $2,300 2024-10-28
Prison Management System HIGH 8.8
CVE-2024-48594

File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.

No fix yet
Fix from $1,950 2024-10-28
Plugin Propagator CRITICAL 9.8
CVE-2024-50495

Unrestricted Upload of File with Dangerous Type vulnerability in nunomorgadinho Plugin Propagator wp-propagator allows Upload a Web Shell to a Web Se…

Fix: after 0.1
Fix from $2,300 2024-10-28
Harmony CRITICAL 9.8
CVE-2024-50623 KEVEPSS 99%

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could …

Fix: 5.8.0.21+
Fix from $2,300 2024-10-28