Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Machform CRITICAL 9.9
CVE-2024-37762

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

Fix: 21+
Fix from $2,300 2024-07-01
Cloud MEDIUM 6.5
CVE-2024-36987

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged …

Fix: 9.0.10 / 9.1.5+
Fix from $1,600 2024-07-01
Unclassified HIGH 7.2
CVE-2024-3123

CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator priv…

Mitigation only
Fix from $1,950 2024-07-01
Unclassified CRITICAL 9.8
CVE-2024-6127EPSS 10%

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker ca…

Mitigation only
Fix from $2,300 2024-06-27
Online Food Ordering System CRITICAL 9.8
CVE-2024-6373

A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vulnerability affects unknown c…

No fix yet
Fix from $2,300 2024-06-27
Auto Featured Image HIGH 8.8
CVE-2024-6054

The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachme…

Fix: after 1.2
Fix from $1,950 2024-06-27
Unclassified CRITICAL 9.8
CVE-2024-35527

An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execut…

Mitigation only
Fix from $2,300 2024-06-25
Whatsup Gold HIGH 8.8
CVE-2024-5008EPSS 17%

In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Ip Office CRITICAL 9.8
CVE-2024-4197

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component…

Fix: 11.1.3.1+
Fix from $2,300 2024-06-25
Instawp Connect CRITICAL 9.8
CVE-2024-37228

Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a…

Fix: 0.1.0.39+
Fix from $2,300 2024-06-24
Bludit HIGH 8.8
CVE-2024-24551

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulner…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Bludit HIGH 8.1
CVE-2024-24550

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Simple Online Bidding System CRITICAL 9.8
CVE-2024-6280

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the…

No fix yet
Fix from $2,300 2024-06-24
Squeeze HIGH 7.2
CVE-2024-35767

Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a…

Fix: 1.4.1+
Fix from $1,950 2024-06-21
Adminerevo CRITICAL 9.8
CVE-2023-45197

The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. …

Fix: 4.8.3+
Fix from $2,300 2024-06-21
Unclassified HIGH 7.4
CVE-2024-28147

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that inc…

No fix yet
Fix from $1,950 2024-06-20
Unclassified CRITICAL 10.0
CVE-2024-34990

In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload …

Mitigation only
Fix from $2,300 2024-06-19
Unclassified CRITICAL 9.8
CVE-2024-33836

In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In v…

Mitigation only
Fix from $2,300 2024-06-19
Unclassified HIGH 8.8
CVE-2024-22263EPSS 18%

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the abili…

Mitigation only
Fix from $1,950 2024-06-19
Sirv HIGH 8.8
CVE-2024-5853

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s…

Fix: 7.2.7+
Fix from $1,950 2024-06-19
Unclassified HIGH 8.8
CVE-2024-6132

The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'pexels_fsp_ima…

Mitigation only
Fix from $1,950 2024-06-19
Salon Booking System CRITICAL 9.8
CVE-2024-3229

The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_Impo…

Fix: 10.3+
Fix from $2,300 2024-06-19
Aliexpress Dropshipping With Alinext HIGH 8.8
CVE-2024-2381

The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the…

Fix: 3.3.6+
Fix from $1,950 2024-06-19
Simple Online Hotel Reservation System CRITICAL 9.8
CVE-2024-6116

A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue …

No fix yet
Fix from $2,300 2024-06-18
Simple Online Hotel Reservation System CRITICAL 9.8
CVE-2024-6115

A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unk…

No fix yet
Fix from $2,300 2024-06-18
Monbela Tourist Inn Online Reservation System CRITICAL 9.8
CVE-2024-6114

A vulnerability classified as critical has been found in itsourcecode Monbela Tourist Inn Online Reservation System up to 1.0. Affected is an unknown…

No fix yet
Fix from $2,300 2024-06-18
Magbanua Beach Resort Online Reservation System CRITICAL 9.8
CVE-2024-6110

A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this …

No fix yet
Fix from $2,300 2024-06-18
Pool Of Bethesda Online Reservation System CRITICAL 9.8
CVE-2024-6084

A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vuln…

No fix yet
Fix from $2,300 2024-06-18
Phpvibe CRITICAL 9.8
CVE-2024-6083

A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp…

Mitigation only
Fix from $2,300 2024-06-18
Payroll Management System CRITICAL 9.8
CVE-2024-34833

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated …

No fix yet
Fix from $2,300 2024-06-17