Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Mstore Api HIGH 8.8
CVE-2024-8242

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type …

Fix: 4.15.4+
Fix from $1,950 2024-09-13
Soplanning CRITICAL 9.8
CVE-2024-27115

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker ca…

Fix: 1.52.02+
Fix from $2,300 2024-09-11
Unclassified HIGH 7.5
CVE-2024-8232EPSS 13%

SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.

Mitigation only
Fix from $1,950 2024-09-10
Mozilocms HIGH 7.2
CVE-2024-44871EPSS 16%

An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a…

No fix yet
Fix from $1,950 2024-09-10
File Manager HIGH 8.8
CVE-2024-7770

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file upload…

Fix: 6.5.6+
Fix from $1,950 2024-09-10
Qualitor CRITICAL 9.8
CVE-2024-44849EPSS 46%

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

No fix yet
Fix from $2,300 2024-09-09
Customizer Export\/import MEDIUM 6.6
CVE-2024-7620

The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_import' functi…

Fix: 0.9.7.1+
Fix from $1,600 2024-09-07
C Mor Video Surveillance HIGH 8.8
CVE-2024-45171

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous fil…

No fix yet
Fix from $1,950 2024-09-05
Job Portal HIGH 8.8
CVE-2024-8463

File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an …

Mitigation only
Fix from $1,950 2024-09-05
Webmethods Integration CRITICAL 9.9
CVE-2024-45076

IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying op…

Mitigation only
Fix from $2,300 2024-09-04
Mcms HIGH 8.1
CVE-2024-42991

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

No fix yet
Fix from $1,950 2024-09-03
Pet Shop Management System HIGH 8.8
CVE-2024-8342

A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This issue affects some unknown pr…

No fix yet
Fix from $1,950 2024-08-30
Pet Shop Management System CRITICAL 9.8
CVE-2024-8341

A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability affects unknown code of the file…

No fix yet
Fix from $2,300 2024-08-30
Shudong Share HIGH 8.8
CVE-2024-8338

A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality o…

Mitigation only
Fix from $1,950 2024-08-30
6shr System HIGH 8.8
CVE-2024-8330

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web sh…

Mitigation only
Fix from $1,950 2024-08-30
Feehicms CRITICAL 9.8
CVE-2024-8296

A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=u…

Fix: after 2.1.1
Fix from $2,300 2024-08-29
Feehicms CRITICAL 9.8
CVE-2024-8295

A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /…

Fix: after 2.1.1
Fix from $2,300 2024-08-29
Feehicms CRITICAL 9.8
CVE-2024-8294

A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r…

Fix: after 2.1.1
Fix from $2,300 2024-08-29
Funnelforms Free HIGH 7.2
CVE-2024-6311

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function …

Fix: after 3.7.3.2
Fix from $1,950 2024-08-28
Zipped Folder Manager App CRITICAL 9.8
CVE-2024-8170

A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects an unknown part of the file /e…

No fix yet
Fix from $2,300 2024-08-26
Thinmanager Thinserver HIGH 7.8
CVE-2024-7987

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code…

Fix: 11.1.8 / 11.2.9+
Fix from $1,950 2024-08-26
Beikeshop HIGH 8.8
CVE-2024-8164

A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function rename of the file /Admin/Htt…

Fix: after 1.5.5
Fix from $1,950 2024-08-26
Publiccms HIGH 7.2
CVE-2024-42523

publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

Fix: after 4.0.202302.e
Fix from $1,950 2024-08-23
File Manager Pro HIGH 8.8
CVE-2024-7559

The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk…

Fix: after 8.3.7
Fix from $1,950 2024-08-23
E Commerce System CRITICAL 9.8
CVE-2024-8089

A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /e…

No fix yet
Fix from $2,300 2024-08-23
Versa Director HIGH 7.2
CVE-2024-39717 KEV

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with …

Mitigation only
Fix from $1,950 2024-08-22
Hotel Management System HIGH 7.2
CVE-2024-42767

Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

No fix yet
Fix from $1,950 2024-08-22
Acymailing HIGH 8.8
CVE-2024-7384

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file u…

Fix: 9.8.0+
Fix from $1,950 2024-08-22
Music Management System HIGH 8.8
CVE-2024-42778

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows …

No fix yet
Fix from $1,950 2024-08-21
Music Management System HIGH 8.8
CVE-2024-42779

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows att…

No fix yet
Fix from $1,950 2024-08-21