Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Crm Perks Forms HIGH 7.2
CVE-2024-7484

The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' f…

Fix: 1.1.4+
Fix from $1,950 2024-08-06
Laravel Accounting System CRITICAL 9.8
CVE-2024-7495

A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file …

No fix yet
Fix from $2,300 2024-08-06
Meetinghub Paperless Meetings HIGH 8.8
CVE-2024-6117

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows …

Mitigation only
Fix from $1,950 2024-08-05
Placement Management System HIGH 8.8
CVE-2024-7450

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unkno…

No fix yet
Fix from $1,950 2024-08-04
Unclassified CRITICAL 9.8
CVE-2024-7257

The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Mitigation only
Fix from $2,300 2024-08-03
Ueditor MEDIUM 6.1
CVE-2024-7342

A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/cont…

Fix: after 1.4.3.3
Fix from $1,600 2024-08-01
Unclassified MEDIUM 6.8
CVE-2024-34021

Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the …

Mitigation only
Fix from $1,600 2024-08-01
Youdiancms CRITICAL 9.8
CVE-2024-7329

A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/mu…

No fix yet
Fix from $2,300 2024-07-31
Fogproject HIGH 8.8
CVE-2024-40645

FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute…

Fix: after 1.5.10.41
Fix from $1,950 2024-07-31
Restaurant Management System HIGH 7.2
CVE-2024-7277

A vulnerability was found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this issue is some unknown functionalit…

No fix yet
Fix from $1,950 2024-07-31
Admidio HIGH 8.8
CVE-2024-38529

Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote C…

Fix: 4.3.10+
Fix from $1,950 2024-07-29
Society Management System HIGH 8.8
CVE-2024-7192

A vulnerability, which was classified as critical, was found in itsourcecode Society Management System 1.0. This affects an unknown part of the file …

No fix yet
Fix from $1,950 2024-07-29
Online Food Ordering System CRITICAL 9.8
CVE-2024-7189

A vulnerability classified as critical has been found in itsourcecode Online Food Ordering System 1.0. Affected is an unknown function of the file ed…

No fix yet
Fix from $2,300 2024-07-29
Profile Builder CRITICAL 9.1
CVE-2024-6366EPSS 29%

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via…

Fix: 3.11.8+
Fix from $2,300 2024-07-29
Cervantes MEDIUM 5.4
CVE-2024-42054

Cervantes through 0.5-alpha accepts insecure file uploads.

Patch available
Fix from $1,600 2024-07-28
Unclassified HIGH 8.8
CVE-2024-6431

The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and missing capability che…

Mitigation only
Fix from $1,950 2024-07-27
Qloapps HIGH 7.2
CVE-2024-40318

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

No fix yet
Fix from $1,950 2024-07-25
Social Auto Poster HIGH 8.8
CVE-2024-6756

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_i…

Fix: 5.3.15+
Fix from $1,950 2024-07-24
Unclassified HIGH 7.2
CVE-2024-6828

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the…

Mitigation only
Fix from $1,950 2024-07-23
University Management System HIGH 8.8
CVE-2024-6958

A vulnerability classified as critical was found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the fil…

No fix yet
Fix from $1,950 2024-07-21
Wuhu CRITICAL 9.8
CVE-2024-6948

A vulnerability classified as critical has been found in Gargaj wuhu up to 3faad49bfcc3895e9ff76a591d05c8941273d120. Affected is an unknown function …

Fix: after 2024-02-10
Fix from $2,300 2024-07-21
Flute CRITICAL 9.8
CVE-2024-6945

A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been classified as critical. This affects an unknown part of the file app/Core/Http/Cont…

Mitigation only
Fix from $2,300 2024-07-21
Automad HIGH 8.8
CVE-2024-40400

An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.

Fix: after 1.10.9
Fix from $1,950 2024-07-19
Brizy HIGH 8.8
CVE-2024-3242

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageCo…

Fix: 2.4.45+
Fix from $1,950 2024-07-18
Identity Services Engine HIGH 7.2
CVE-2024-20296

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload…

Fix: 3.1+
Fix from $1,950 2024-07-17
Manageengine Ddi Central HIGH 8.8
CVE-2024-27311

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new fi…

Fix: 4002+
Fix from $1,950 2024-07-17
Streampipes HIGH 8.8
CVE-2024-31411

Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead …

Fix: 0.95.0+
Fix from $1,950 2024-07-17
Keydatas CRITICAL 9.8
CVE-2024-6220EPSS 36%

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadIm…

Fix: after 2.5.2
Fix from $2,300 2024-07-17
GitLab MEDIUM 5.3
CVE-2024-6595

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting …

Fix: 16.11.6 / 17.0.4+
Fix from $1,600 2024-07-17
Online Student Management System CRITICAL 9.8
CVE-2024-6801

A vulnerability, which was classified as critical, has been found in SourceCodester Online Student Management System 1.0. This issue affects some unk…

No fix yet
Fix from $2,300 2024-07-17