Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.8
CVE-2024-3912

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to …

Mitigation only
Fix from $2,300 2024-06-14
Download Master HIGH 7.2
CVE-2024-31161

The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this…

Fix: 3.1.0.114+
Fix from $1,950 2024-06-14
Openeclass CRITICAL 9.8
CVE-2024-31777

File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoi…

Fix: after 3.15
Fix from $2,300 2024-06-13
Workforce Optimization HIGH 8.8
CVE-2024-36396

Verint - CWE-434: Unrestricted Upload of File with Dangerous Type

Fix: 15.2.1030+
Fix from $1,950 2024-06-13
Commerce HIGH 7.2
CVE-2024-34110

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerabil…

Fix: after 1.4.0
Fix from $1,950 2024-06-13
Megabip CRITICAL 9.8
CVE-2024-1659

Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authe…

Fix: after 5.10
Fix from $2,300 2024-06-12
Document Builder MEDIUM 6.5
CVE-2024-34683

An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to a…

Patch available
Fix from $1,600 2024-06-11
Suitecrm HIGH 8.8
CVE-2024-36415

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in upload…

Fix: 7.14.4 / 8.6.1+
Fix from $1,950 2024-06-10
Buddypress Cover CRITICAL 9.8
CVE-2024-35746

Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects BuddyPres…

Fix: after 2.1.4.2
Fix from $2,300 2024-06-10
Engineering Lifecycle Optimization Publishing CRITICAL 9.8
CVE-2023-45188

IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali…

Mitigation only
Fix from $2,300 2024-06-09
Bakery Online Ordering System CRITICAL 9.8
CVE-2024-5745

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affected is an unknown function of t…

No fix yet
Fix from $2,300 2024-06-07
Online Discussion Forum HIGH 8.8
CVE-2024-5734

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknown function of the file /membe…

No fix yet
Fix from $1,950 2024-06-07
Monstra HIGH 7.2
CVE-2024-36774

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

No fix yet
Fix from $1,950 2024-06-06
Chuanhuchatgpt MEDIUM 6.1
CVE-2024-5278

gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/…

Fix: 20240919+
Fix from $1,600 2024-06-06
Jan CRITICAL 9.8
CVE-2024-37273

An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2024-06-04
Jan CRITICAL 9.8
CVE-2024-36858

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading…

No fix yet
Fix from $2,300 2024-06-04
Unlimited Elements For Elementor HIGH 7.2
CVE-2023-33930

Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates…

Fix: 1.5.67+
Fix from $1,950 2024-06-04
Insert Or Embed Articulate Content MEDIUM 5.4
CVE-2024-0757

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be i…

Fix: after 4.3000000023
Fix from $1,600 2024-06-04
Nas326 Firmware CRITICAL 9.8
CVE-2024-29974EPSS 23%

** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before…

Fix: 5.21+
Fix from $2,300 2024-06-04
Avalanche HIGH 7.2
CVE-2024-29848EPSS 64%

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbit…

Fix: 6.4.3.602+
Fix from $1,950 2024-05-31
Online Discussion Forum HIGH 8.8
CVE-2024-5518

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_pr…

No fix yet
Fix from $1,950 2024-05-30
Unclassified CRITICAL 9.1
CVE-2024-3412

The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty…

Mitigation only
Fix from $2,300 2024-05-29
Tcpdf HIGH 7.5
CVE-2024-22641

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

Fix: after 6.7.4
Fix from $1,950 2024-05-28
Dedecms CRITICAL 9.8
CVE-2024-35510

An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading …

No fix yet
Fix from $2,300 2024-05-28
Unclassified HIGH 8.1
CVE-2023-46694

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due …

Mitigation only
Fix from $1,950 2024-05-28
Vdesk HIGH 8.8
CVE-2022-45171

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShar…

Fix: after 018
Fix from $1,950 2024-05-28
Vehicle Management System CRITICAL 9.8
CVE-2024-5377

A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affects an unknown part of the fi…

No fix yet
Fix from $2,300 2024-05-26
Unclassified MEDIUM 5.5
CVE-2024-35593

An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arbitrary code via uploading a c…

Mitigation only
Fix from $1,600 2024-05-24
Custom Fonts MEDIUM 5.4
CVE-2024-1332

The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up t…

Fix: 2.1.5+
Fix from $1,600 2024-05-24
Prosafe Network Management System HIGH 8.8
CVE-2024-5247EPSS 27%

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remot…

Fix: 1.7.0.37+
Fix from $1,950 2024-05-23