Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Inxedu CRITICAL 9.8
CVE-2024-35079

An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted…

Mitigation only
Fix from $2,300 2024-05-23
Inxedu CRITICAL 9.8
CVE-2024-35080

An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp f…

Mitigation only
Fix from $2,300 2024-05-23
Dedecms CRITICAL 9.8
CVE-2024-35375

There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

Mitigation only
Fix from $2,300 2024-05-23
Inxedu CRITICAL 9.8
CVE-2024-35570

An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute arbitrar…

No fix yet
Fix from $2,300 2024-05-23
Hash Form CRITICAL 9.8
CVE-2024-5084EPSS 51%

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fil…

Fix: 1.1.1+
Fix from $2,300 2024-05-23
Vehicle Management System HIGH 8.8
CVE-2024-5145

A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue affects some unknown processin…

No fix yet
Fix from $1,950 2024-05-20
E Commerce Site HIGH 8.8
CVE-2024-5049

A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionali…

No fix yet
Fix from $1,950 2024-05-17
Unclassified MEDIUM 6.3
CVE-2024-5050

A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=lo…

Mitigation only
Fix from $1,600 2024-05-17
Student Management System CRITICAL 9.8
CVE-2024-5047

A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an unknown function of the file /s…

No fix yet
Fix from $2,300 2024-05-17
Lylme Spage CRITICAL 9.8
CVE-2024-34982

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via upload…

No fix yet
Fix from $2,300 2024-05-17
Emlog HIGH 8.8
CVE-2024-5043

A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setti…

No fix yet
Fix from $1,950 2024-05-17
Unclassified CRITICAL 10.0
CVE-2024-32809

Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveD…

Mitigation only
Fix from $2,300 2024-05-17
Copymatic CRITICAL 9.8
CVE-2024-31351

Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – A…

Fix: 1.7+
Fix from $2,300 2024-05-17
Xstore Core CRITICAL 9.8
CVE-2024-33556

Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.

Fix: 5.3.9+
Fix from $2,300 2024-05-17
Js Help Desk CRITICAL 9.1
CVE-2023-25444

Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Using Malicious F…

Fix: 2.7.8+
Fix from $2,300 2024-05-17
Schoolwebtech CRITICAL 9.8
CVE-2024-4966

A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /impro…

No fix yet
Fix from $2,300 2024-05-16
Dar 7000 Firmware CRITICAL 9.8
CVE-2024-4964

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This vulnerability affe…

Mitigation only
Fix from $2,300 2024-05-16
Dar 7000 Firmware CRITICAL 9.8
CVE-2024-4963

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000-40 V31R02B1413C. This affects an unkn…

Mitigation only
Fix from $2,300 2024-05-16
Dar 7000 Firmware CRITICAL 9.8
CVE-2024-4962

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by thi…

Mitigation only
Fix from $2,300 2024-05-16
Dar 7000 Firmware CRITICAL 9.8
CVE-2024-4961

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability i…

Mitigation only
Fix from $2,300 2024-05-16
Dar 7000 Firmware CRITICAL 9.8
CVE-2024-4960

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown func…

Mitigation only
Fix from $2,300 2024-05-16
Online Art Gallery Management System HIGH 8.8
CVE-2024-4946

A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerabilit…

No fix yet
Fix from $1,950 2024-05-16
Best Courier Management System CRITICAL 9.8
CVE-2024-4945

A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown functio…

No fix yet
Fix from $2,300 2024-05-16
Simple Online Bidding System CRITICAL 9.8
CVE-2024-4927

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an …

No fix yet
Fix from $2,300 2024-05-16
E Commerce Site HIGH 8.8
CVE-2024-4923

A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/…

No fix yet
Fix from $1,950 2024-05-16
Employee And Visitor Gate Pass Logging System CRITICAL 9.8
CVE-2024-4921

A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown fun…

No fix yet
Fix from $2,300 2024-05-16
Online Discussion Forum Site CRITICAL 9.8
CVE-2024-4920

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processi…

No fix yet
Fix from $2,300 2024-05-16
Dootask MEDIUM 5.4
CVE-2024-34906

An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.

No fix yet
Fix from $1,600 2024-05-15
Kykms MEDIUM 5.4
CVE-2024-34909

An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.

Fix: after 1.0.1
Fix from $1,600 2024-05-15
R Pan Scaffolding MEDIUM 5.4
CVE-2024-34913

An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF fil…

Fix: after 5.0
Fix from $1,600 2024-05-15