Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 10.0
CVE-2024-49291

Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro: from n/a before 1.8.0.

Mitigation only
Fix from $2,300 2024-10-17
Unclassified HIGH 8.8
CVE-2024-49398

The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.

Mitigation only
Fix from $1,950 2024-10-17
Classcms CRITICAL 9.8
CVE-2024-48180

ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template di…

Fix: after 4.8
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.9
CVE-2024-49260

Unrestricted Upload of File with Dangerous Type vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery allows Code Inje…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 10.0
CVE-2024-49242

Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.Thi…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.9
CVE-2024-48034

Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipbook-from-pdf allows Upload a …

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.9
CVE-2024-48035

Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-search-and-insert allows Upload a …

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 10.0
CVE-2024-49216

Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allows Upload a Web Shell to a Web…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.9
CVE-2024-48027

Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-featured-image-from-bing allow…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.1
CVE-2024-47649

Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: from n/a through <= 1.2.4.

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 10.0
CVE-2024-49257

Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Upload a Web Shell to a Web Serve…

Mitigation only
Fix from $2,300 2024-10-16
Migration\, Backup\, Staging HIGH 8.8
CVE-2020-36842

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the wpvivi…

Fix: after 0.9.35
Fix from $1,950 2024-10-16
Frontend File Manager CRITICAL 9.8
CVE-2016-15042EPSS 6%

The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploa…

Fix: 1.1 / 4.0+
Fix from $2,300 2024-10-16
File Manager HIGH 8.8
CVE-2024-8746

The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'm…

Fix: 8.3.10+
Fix from $1,950 2024-10-16
File Manager MEDIUM 5.4
CVE-2024-8918

The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to…

Fix: 8.3.10+
Fix from $1,600 2024-10-16
Zoomsounds CRITICAL 9.8
CVE-2021-4449EPSS 5%

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions…

Fix: after 5.96
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.8
CVE-2021-4443

The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save A…

Mitigation only
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.8
CVE-2024-48781

An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constru…

Mitigation only
Fix from $2,300 2024-10-15
Unclassified CRITICAL 9.8
CVE-2024-48782

File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detectin…

Mitigation only
Fix from $2,300 2024-10-15
Drag And Drop Image Upload HIGH 8.8
CVE-2024-9975

A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown fun…

No fix yet
Fix from $1,950 2024-10-15
Enterprise Cloud Database CRITICAL 9.8
CVE-2024-9985

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell an…

Fix: 2024-08-08+
Fix from $2,300 2024-10-15
Ee Class HIGH 8.8
CVE-2024-9981

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a mal…

Fix: 2024-03-26+
Fix from $1,950 2024-10-15
07flycms HIGH 7.2
CVE-2024-9904

A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUplo…

Fix: after 1.2.0
Fix from $1,950 2024-10-13
07flycms HIGH 7.2
CVE-2024-9903

A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the fi…

Fix: after 1.2.0
Fix from $1,950 2024-10-12
Unclassified CRITICAL 9.8
CVE-2024-42640EPSS 43%

angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allo…

Mitigation only
Fix from $2,300 2024-10-11
Unclassified CRITICAL 9.8
CVE-2024-46088

An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v…

Mitigation only
Fix from $2,300 2024-10-11
07flycms HIGH 7.2
CVE-2024-9855

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function…

No fix yet
Fix from $1,950 2024-10-11
Tourist Management System HIGH 7.2
CVE-2024-9816

A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality …

No fix yet
Fix from $1,950 2024-10-10
Tourist Management System HIGH 7.2
CVE-2024-9815

A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown fun…

No fix yet
Fix from $1,950 2024-10-10
Online Shopping Portal CRITICAL 9.8
CVE-2024-9794

A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue affects some unknown processing …

No fix yet
Fix from $2,300 2024-10-10