Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Simple Library Management System CRITICAL 9.8
CVE-2024-40394

Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax…

No fix yet
Fix from $2,300 2024-07-16
Sparkshop CRITICAL 9.8
CVE-2024-40425

File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute ar…

Fix: 1.1.7+
Fix from $2,300 2024-07-16
Tmall Demo MEDIUM 5.3
CVE-2024-40555

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.

No fix yet
Fix from $1,600 2024-07-15
Insert Or Embed Articulate Content HIGH 8.8
CVE-2024-5630

The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site,…

Fix: 4.3000000024+
Fix from $1,950 2024-07-15
Unclassified MEDIUM 6.3
CVE-2024-6730

A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown proc…

Mitigation only
Fix from $1,600 2024-07-14
Wp Emember HIGH 8.8
CVE-2024-5080

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP …

Fix: 10.6.6+
Fix from $1,950 2024-07-13
Bug Library CRITICAL 9.1
CVE-2024-5450

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload …

Fix: 2.1.1+
Fix from $2,300 2024-07-13
Publiccms HIGH 8.8
CVE-2024-40545

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary c…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40546

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code …

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40548

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40549

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40550

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40551

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary …

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Unclassified CRITICAL 9.1
CVE-2024-38736

Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realty…

Mitigation only
Fix from $2,300 2024-07-12
Unclassified CRITICAL 9.1
CVE-2024-38734

Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.…

Mitigation only
Fix from $2,300 2024-07-12
File Manager Advanced Shortcode HIGH 8.8
CVE-2023-7061

The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This m…

Fix: after 2.5.3
Fix from $1,950 2024-07-10
Sinema Remote Connect Server HIGH 8.8
CVE-2024-39865

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encryp…

Fix: 3.2+
Fix from $1,950 2024-07-09
Unclassified CRITICAL 9.9
CVE-2024-37424

Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affe…

Mitigation only
Fix from $2,300 2024-07-09
Church Admin CRITICAL 9.9
CVE-2024-37418

Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a throu…

Fix: 4.4.7+
Fix from $2,300 2024-07-09
Unclassified CRITICAL 9.9
CVE-2024-37420

Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web Shell to a Web Server.This is…

Mitigation only
Fix from $2,300 2024-07-09
Unclassified CRITICAL 9.8
CVE-2024-6314

The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process_image_uploa…

Mitigation only
Fix from $2,300 2024-07-09
Unclassified HIGH 8.8
CVE-2024-6161

The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'get_cache_image' …

Mitigation only
Fix from $1,950 2024-07-09
Unclassified CRITICAL 9.8
CVE-2024-6313

The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' …

Mitigation only
Fix from $2,300 2024-07-09
Generate Pdf Using Contact Form 7 CRITICAL 9.8
CVE-2024-37555

Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This …

Fix: after 4.0.9
Fix from $2,300 2024-07-09
Unclassified HIGH 7.2
CVE-2024-6123

The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all ver…

Mitigation only
Fix from $1,950 2024-07-09
Modern Events Calendar Lite HIGH 8.8
CVE-2024-5441

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image…

Fix: 7.12.0+
Fix from $1,950 2024-07-09
Openvpn CRITICAL 9.8
CVE-2024-27903EPSS 9%

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in …

Fix: 2.5.10 / 2.6.10+
Fix from $2,300 2024-07-08
Imgspider HIGH 8.8
CVE-2024-6319

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versio…

Fix: 2.3.11+
Fix from $1,950 2024-07-04
Imgspider HIGH 8.8
CVE-2024-6318

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in a…

Fix: 2.3.11+
Fix from $1,950 2024-07-04
Home Owners Collection Management System CRITICAL 9.8
CVE-2024-6439

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown …

No fix yet
Fix from $2,300 2024-07-02