Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Music Management System HIGH 8.8
CVE-2024-42780

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows att…

No fix yet
Fix from $1,950 2024-08-21
Music Management System CRITICAL 9.8
CVE-2024-42777

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attack…

No fix yet
Fix from $2,300 2024-08-21
Erp CRITICAL 9.8
CVE-2024-42563

An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.

Fix: after 2018-03-02
Fix from $2,300 2024-08-20
Unclassified HIGH 7.2
CVE-2022-1206

The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extens…

Mitigation only
Fix from $1,950 2024-08-20
Laravel Property Management System HIGH 8.8
CVE-2024-7944

A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been classified as critical. Affected is the function Update…

Mitigation only
Fix from $1,950 2024-08-20
Laravel Property Management System HIGH 8.8
CVE-2024-7943

A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload o…

No fix yet
Fix from $1,950 2024-08-20
Bit Form HIGH 8.8
CVE-2024-43249

Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from…

Fix: after 2.6.4
Fix from $1,950 2024-08-19
Douphp HIGH 7.2
CVE-2024-7917

A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionalit…

No fix yet
Fix from $1,950 2024-08-18
Online Railway Reservation System HIGH 7.2
CVE-2024-7910

A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by this issue is some unknown funct…

No fix yet
Fix from $1,950 2024-08-18
Dedebiz HIGH 8.8
CVE-2024-7906

A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type of the file /admin/dialog/se…

Mitigation only
Fix from $1,950 2024-08-18
Dedebiz HIGH 7.2
CVE-2024-7905

A vulnerability classified as critical has been found in DedeBIZ 6.3.0. This affects the function AdminUpload of the file admin/archives_do.php. The …

No fix yet
Fix from $1,950 2024-08-18
Dedebiz HIGH 8.8
CVE-2024-7904

A vulnerability was found in DedeBIZ 6.3.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/fil…

No fix yet
Fix from $1,950 2024-08-18
Dedebiz HIGH 8.8
CVE-2024-7903

A vulnerability was found in DedeBIZ 6.3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

No fix yet
Fix from $1,950 2024-08-18
Metform Elementor Contact Form Builder CRITICAL 9.8
CVE-2023-0714

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions …

Fix: 3.3.0+
Fix from $2,300 2024-08-17
Enterprise Resource Management System HIGH 8.8
CVE-2024-42676

File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the…

Fix: after 1.0
Fix from $1,950 2024-08-15
Commerce CRITICAL 9.0
CVE-2024-39397

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnera…

Fix: after 2.4.3
Fix from $2,300 2024-08-14
Unclassified HIGH 8.8
CVE-2024-4389

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up…

Mitigation only
Fix from $1,950 2024-08-14
Unclassified CRITICAL 10.0
CVE-2024-43160

Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

Mitigation only
Fix from $2,300 2024-08-13
Media Library Assistant HIGH 8.8
CVE-2024-6823

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline…

Fix: 3.19+
Fix from $1,950 2024-08-13
Mwcms MEDIUM 5.3
CVE-2024-7705

A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the function uploadeditor of the…

Mitigation only
Fix from $1,600 2024-08-12
Openeclass CRITICAL 9.8
CVE-2024-38530

The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save…

Fix: 3.16+
Fix from $2,300 2024-08-12
Threatsonar Anti Ransomware HIGH 7.2
CVE-2024-7694 KEV

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on …

Fix: 3.5.0+
Fix from $1,950 2024-08-12
Magicinfo 9 Server CRITICAL 9.8
CVE-2024-7399 KEVEPSS 92%

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wr…

Fix: 21.1050.0+
Fix from $2,300 2024-08-12
Unclassified CRITICAL 9.8
CVE-2024-41577

An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a c…

Mitigation only
Fix from $2,300 2024-08-12
Fuse Social Floating Sidebar MEDIUM 5.4
CVE-2024-5226

The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions …

Fix: 5.4.11+
Fix from $1,600 2024-08-08
Open Webui HIGH 8.8
CVE-2024-6707

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

No fix yet
Fix from $1,950 2024-08-07
Poly Clariti Manager HIGH 8.8
CVE-2024-41913

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize …

Fix: 10.12.0.2_100+
Fix from $1,950 2024-08-06
Tailoring Management System HIGH 8.8
CVE-2024-7506

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unkno…

No fix yet
Fix from $1,950 2024-08-06
Airline Reservation System CRITICAL 9.8
CVE-2024-7500

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_…

No fix yet
Fix from $2,300 2024-08-06
Unclassified HIGH 8.8
CVE-2024-6315

The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' func…

Mitigation only
Fix from $1,950 2024-08-06