Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Attendance And Payroll System CRITICAL 9.8
CVE-2024-10420

A vulnerability classified as critical has been found in SourceCodester Attendance and Payroll System 1.0. This affects the function upload of the fi…

Mitigation only
Fix from $2,300 2024-10-27
Online Hotel Reservation System CRITICAL 9.8
CVE-2024-10413

A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is th…

Mitigation only
Fix from $2,300 2024-10-27
Online Hotel Reservation System HIGH 7.2
CVE-2024-10410

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the functio…

No fix yet
Fix from $1,950 2024-10-27
Unclassified CRITICAL 9.8
CVE-2024-9932EPSS 36%

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNe…

Mitigation only
Fix from $2,300 2024-10-26
Mango HIGH 8.8
CVE-2024-37847

An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted fi…

Fix: 4.5.5 / 5.1.4+
Fix from $1,950 2024-10-25
Mt6000 Firmware HIGH 8.8
CVE-2024-45263

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uplo…

Fix: 4.6.4+
Fix from $1,950 2024-10-24
Purchase Order Management System HIGH 7.2
CVE-2024-48454

An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

Mitigation only
Fix from $1,950 2024-10-24
Unclassified MEDIUM 6.6
CVE-2024-49676

Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor custom-icons-for-elementor allows Upload a…

Mitigation only
Fix from $1,600 2024-10-23
Unclassified CRITICAL 9.9
CVE-2024-49671

Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images – AI Postpix ai-po…

Mitigation only
Fix from $2,300 2024-10-23
Unclassified CRITICAL 9.9
CVE-2024-49669

Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Upload a Web Shell to a Web Ser…

Mitigation only
Fix from $2,300 2024-10-23
Unclassified CRITICAL 9.9
CVE-2024-49652

Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Upload a Web S…

Mitigation only
Fix from $2,300 2024-10-23
Unclassified CRITICAL 9.9
CVE-2024-49653

Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This is…

Mitigation only
Fix from $2,300 2024-10-23
Unclassified CRITICAL 9.9
CVE-2024-49658

Unrestricted Upload of File with Dangerous Type vulnerability in ecomerciar Woocommerce Custom Profile Picture woo-custom-profile-picture allows Uplo…

Mitigation only
Fix from $2,300 2024-10-23
Unclassified CRITICAL 10.0
CVE-2024-49668

Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web S…

Mitigation only
Fix from $2,300 2024-10-23
Zzcms CRITICAL 9.8
CVE-2024-10293

A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/c…

Mitigation only
Fix from $2,300 2024-10-23
Zzcms CRITICAL 9.8
CVE-2024-10292

A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTab…

Mitigation only
Fix from $2,300 2024-10-23
Unclassified HIGH 8.2
CVE-2024-46482

An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute a…

Mitigation only
Fix from $1,950 2024-10-22
Administrative Management System HIGH 8.8
CVE-2024-10201

Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to…

Mitigation only
Fix from $1,950 2024-10-21
Photokit CRITICAL 9.8
CVE-2024-49610

Unrestricted Upload of File with Dangerous Type vulnerability in photokiteditor photokit photokit allows Upload a Web Shell to a Web Server.This issu…

Fix: after 1.0
Fix from $2,300 2024-10-20
Nice Backgrounds CRITICAL 9.8
CVE-2024-49330

Unrestricted Upload of File with Dangerous Type vulnerability in brx8r Nice Backgrounds nicebackgrounds allows Upload a Web Shell to a Web Server.Thi…

Fix: after 1.0
Fix from $2,300 2024-10-20
Property Lot Management System HIGH 8.8
CVE-2024-49331

Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System plms allows Upload a Web Shell to a …

Fix: after 4.2.38
Fix from $1,950 2024-10-20
Wp Dropbox Dropins CRITICAL 9.8
CVE-2024-49607

Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows Upload a Web Shell to a Web Se…

Fix: after 1.0
Fix from $2,300 2024-10-20
Woostagram Connect CRITICAL 9.8
CVE-2024-49327

Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell to a Web S…

Fix: after 1.0.2
Fix from $2,300 2024-10-20
Wp Rest Api Fns CRITICAL 9.8
CVE-2024-49329

Unrestricted Upload of File with Dangerous Type vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Upload a Web Shell to a Web Serve…

Fix: after 1.0.0
Fix from $2,300 2024-10-20
Sovratec Case Management CRITICAL 9.8
CVE-2024-49324

Unrestricted Upload of File with Dangerous Type vulnerability in sovratecdev Sovratec Case Management sovratec-case-management allows Upload a Web Sh…

Fix: after 1.0.0
Fix from $2,300 2024-10-20
Affiliator CRITICAL 9.8
CVE-2024-49326

Unrestricted Upload of File with Dangerous Type vulnerability in Vasileios Kerasiotis Affiliator affiliator-lite allows Upload a Web Shell to a Web S…

Fix: after 2.1.3
Fix from $2,300 2024-10-20
Product Website Showcase CRITICAL 9.8
CVE-2024-49611

Unrestricted Upload of File with Dangerous Type vulnerability in paxmanpwnz Product Website Showcase product-websites-showcase allows Upload a Web Sh…

Fix: after 1.0
Fix from $2,300 2024-10-20
Boat Booking System HIGH 8.8
CVE-2024-10161

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file change-i…

No fix yet
Fix from $1,950 2024-10-20
Radar CRITICAL 9.8
CVE-2024-10120

A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /service…

Fix: after 1.0.8
Fix from $2,300 2024-10-18
Unclassified CRITICAL 10.0
CVE-2024-49314

Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie JiangQie Free Mini Program jiangqie-free-mini-program allows Upload a Web S…

Mitigation only
Fix from $2,300 2024-10-17