Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Framemaker HIGH 7.8
CVE-2024-47423

Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could resu…

Fix: 2020.7 / 2022.5+
Fix from $1,950 2024-10-09
Incopy HIGH 7.8
CVE-2024-45136

InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitr…

Fix: 18.5.4 / 19.5+
Fix from $1,950 2024-10-09
Indesign HIGH 7.8
CVE-2024-45137

InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result…

Fix: 18.5.4 / 19.5+
Fix from $1,950 2024-10-09
Livewire CRITICAL 9.8
CVE-2024-47823

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and …

Fix: 2.12.7 / 3.5.2+
Fix from $2,300 2024-10-08
Businessobjects Business Intelligence MEDIUM 6.5
CVE-2024-37179

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting…

Mitigation only
Fix from $1,600 2024-10-08
Unclassified HIGH 8.0
CVE-2024-47319

Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form bit-form.This issue affects Bit Form: from n/a through <= 2.13.10.

Mitigation only
Fix from $1,950 2024-10-05
Hash Form MEDIUM 6.1
CVE-2024-9417

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in th…

Fix: 1.2.0+
Fix from $1,600 2024-10-05
Unclassified MEDIUM 6.8
CVE-2024-8743

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript Fi…

Mitigation only
Fix from $1,600 2024-10-05
Online Discussion Forum HIGH 8.8
CVE-2024-37868

File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply…

No fix yet
Fix from $1,950 2024-10-04
Online Discussion Forum HIGH 8.8
CVE-2024-37869

File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.ph…

No fix yet
Fix from $1,950 2024-10-04
Client Dashboard HIGH 8.8
CVE-2024-47655

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An au…

Fix: 9.7.0+
Fix from $1,950 2024-10-04
Contao MEDIUM 5.4
CVE-2024-45965

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5…

Fix: 4.13.54 / 5.3.30+
Fix from $1,600 2024-10-02
Wp Hotel Booking HIGH 8.8
CVE-2024-7855EPSS 18%

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function…

Fix: 2.1.3+
Fix from $1,950 2024-10-02
Unclassified CRITICAL 9.8
CVE-2024-9108

The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remotei…

Mitigation only
Fix from $2,300 2024-10-01
Unclassified HIGH 8.8
CVE-2024-46441

An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/…

Mitigation only
Fix from $1,950 2024-09-27
Kvf Admin CRITICAL 9.8
CVE-2024-9280

A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability a…

Mitigation only
Fix from $2,300 2024-09-27
Agnai HIGH 8.8
CVE-2024-47169

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attac…

Fix: 1.0.330+
Fix from $1,950 2024-09-26
Advanced File Manager HIGH 8.8
CVE-2024-8126

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, …

Fix: 5.2.9+
Fix from $1,950 2024-09-26
Advanced File Manager MEDIUM 5.4
CVE-2024-8725

Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ens…

Fix: 5.2.9+
Fix from $1,600 2024-09-26
Jupiter X Core CRITICAL 9.8
CVE-2024-7772

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function i…

Fix: 4.6.6+
Fix from $2,300 2024-09-26
Scriptcase CRITICAL 9.8
CVE-2024-8940

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plu…

Mitigation only
Fix from $2,300 2024-09-25
Cs Cart Multivendor CRITICAL 9.8
CVE-2023-26686

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a…

No fix yet
Fix from $2,300 2024-09-25
Cs Cart Multivendor HIGH 8.8
CVE-2023-26690

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor…

No fix yet
Fix from $1,950 2024-09-25
Gdidees Cms CRITICAL 9.8
CVE-2024-46101

GDidees CMS <= v3.9.1 has a file upload vulnerability.

Fix: after 3.9.1
Fix from $2,300 2024-09-20
Online Book Store Project MEDIUM 6.3
CVE-2024-9036

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file…

No fix yet
Fix from $1,600 2024-09-20
Online Shopping Portal CRITICAL 9.8
CVE-2024-9038

A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionalit…

No fix yet
Fix from $2,300 2024-09-20
Cless Server CRITICAL 9.8
CVE-2024-40125

An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitr…

No fix yet
Fix from $2,300 2024-09-19
Dedecms HIGH 8.8
CVE-2024-46373

Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.

Mitigation only
Fix from $1,950 2024-09-18
Best House Rental Management System CRITICAL 9.8
CVE-2024-46377

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_clas…

Mitigation only
Fix from $2,300 2024-09-18
Contao HIGH 8.8
CVE-2024-45398

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the…

Fix: 4.13.49 / 5.3.15+
Fix from $1,950 2024-09-17