Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified MEDIUM 6.3
CVE-2024-4904

A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This issue affects some unknown pro…

Mitigation only
Fix from $1,600 2024-05-15
Imanager CRITICAL 9.8
CVE-2024-3488

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a f…

Fix: 3.2.6+
Fix from $2,300 2024-05-15
Imanager CRITICAL 9.8
CVE-2024-3483

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserializat…

Fix: after 3.2.6
Fix from $2,300 2024-05-15
Git CRITICAL 9.0
CVE-2024-32002EPSS 29%

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be c…

Fix: 2.39.4 / 2.40.2+
Fix from $2,300 2024-05-14
Unclassified CRITICAL 9.6
CVE-2024-33006

An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise …

Mitigation only
Fix from $2,300 2024-05-14
Ruggedcom Crossbow HIGH 7.2
CVE-2024-27945

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged u…

Fix: 5.5+
Fix from $1,950 2024-05-14
Ruggedcom Crossbow HIGH 7.2
CVE-2024-27944

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware file…

Fix: 5.5+
Fix from $1,950 2024-05-14
Ruggedcom Crossbow HIGH 7.2
CVE-2024-27943

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files…

Fix: 5.5+
Fix from $1,950 2024-05-14
Cockpit CRITICAL 9.8
CVE-2024-4825

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque…

Mitigation only
Fix from $2,300 2024-05-14
Online Computer And Laptop Store HIGH 8.8
CVE-2024-4820

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is…

No fix yet
Fix from $1,950 2024-05-14
Open Source Clinic Management System CRITICAL 9.8
CVE-2024-4809

A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability …

No fix yet
Fix from $2,300 2024-05-14
Legal Case Management System HIGH 7.2
CVE-2024-4681

A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the fi…

No fix yet
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.8
CVE-2024-4560

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_c…

Mitigation only
Fix from $2,300 2024-05-14
Learnpress HIGH 8.8
CVE-2024-4397

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_p…

Fix: 4.2.6.6+
Fix from $1,950 2024-05-14
Unclassified CRITICAL 10.0
CVE-2024-34555

Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.

Mitigation only
Fix from $2,300 2024-05-14
Ai Engine HIGH 7.2
CVE-2024-34440

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:…

Fix: 2.2.70+
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.1
CVE-2024-34416

Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1.

Mitigation only
Fix from $2,300 2024-05-14
Unclassified CRITICAL 9.9
CVE-2024-34411

Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through…

Mitigation only
Fix from $2,300 2024-05-14
Unclassified CRITICAL 10.0
CVE-2024-32700

Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for W…

Mitigation only
Fix from $2,300 2024-05-14
Unclassified CRITICAL 10.0
CVE-2024-31377

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album …

Mitigation only
Fix from $2,300 2024-05-14
Nocodb MEDIUM 5.4
CVE-2023-50717

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html fi…

Fix: 0.202.10+
Fix from $1,600 2024-05-14
Security Guardium MEDIUM 6.5
CVE-2023-47711

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force…

Mitigation only
Fix from $1,600 2024-05-14
Track It\! HIGH 8.8
CVE-2021-35002

BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…

Mitigation only
Fix from $1,950 2024-05-07
Roothub CRITICAL 9.8
CVE-2024-33120

Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerabili…

Mitigation only
Fix from $2,300 2024-05-07
Unclassified CRITICAL 9.8
CVE-2024-4345

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process'…

Mitigation only
Fix from $2,300 2024-05-07
Emlog MEDIUM 6.3
CVE-2024-33752

An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker…

No fix yet
Fix from $1,600 2024-05-06
Prison Management System HIGH 8.8
CVE-2024-4500

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code o…

No fix yet
Fix from $1,950 2024-05-05
Unclassified CRITICAL 9.8
CVE-2024-33786

An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploadi…

Mitigation only
Fix from $2,300 2024-05-03
Viewpower CRITICAL 9.8
CVE-2023-51590

Voltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers t…

Mitigation only
Fix from $2,300 2024-05-03
Scada Data Gateway MEDIUM 6.5
CVE-2023-39462

Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary fi…

Mitigation only
Fix from $1,600 2024-05-03