Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Scada Data Gateway HIGH 7.2
CVE-2023-39463

Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allo…

Mitigation only
Fix from $1,950 2024-05-03
Prosafe Network Management System HIGH 8.8
CVE-2023-38098EPSS 13%

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remot…

Fix: 1.7.0.20+
Fix from $1,950 2024-05-03
Prosafe Network Management System HIGH 8.8
CVE-2023-38095EPSS 66%

NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allo…

Fix: 1.7.0.20+
Fix from $1,950 2024-05-03
Unclassified HIGH 8.8
CVE-2024-4033

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_att…

Mitigation only
Fix from $1,950 2024-05-02
Instawp Connect CRITICAL 9.8
CVE-2024-2667EPSS 6%

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio…

Fix: 0.1.0.23+
Fix from $2,300 2024-05-02
Royal Elementor Addons CRITICAL 9.8
CVE-2024-1567

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_…

Fix: 1.3.95+
Fix from $2,300 2024-05-02
Pisay Online E Learning System HIGH 7.3
CVE-2024-4349

A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an …

No fix yet
Fix from $1,950 2024-04-30
Unclassified HIGH 7.2
CVE-2024-28269

ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to uploa…

Mitigation only
Fix from $1,950 2024-04-30
Cubecart HIGH 8.0
CVE-2024-33438

File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.

Fix: 6.5.5+
Fix from $1,950 2024-04-29
Hubbank HIGH 8.8
CVE-2024-4306

Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious P…

Mitigation only
Fix from $1,950 2024-04-29
Pyload HIGH 7.2
CVE-2024-32880

pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template …

Fix: after 0.5.0
Fix from $1,950 2024-04-26
Product Addons \& Fields For Woocommerce CRITICAL 9.8
CVE-2024-3962

The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the p…

Fix: 32.0.19+
Fix from $2,300 2024-04-26
Unclassified CRITICAL 10.0
CVE-2024-0916

Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

Patch available
Fix from $2,300 2024-04-25
Simple School Management System MEDIUM 6.3
CVE-2024-31610

File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to r…

No fix yet
Fix from $1,600 2024-04-25
Thinkcmf CRITICAL 9.8
CVE-2024-31615

ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

No fix yet
Fix from $2,300 2024-04-25
Unlimited Elements For Elementor HIGH 8.8
CVE-2023-31090

Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates…

Fix: 1.5.61+
Fix from $1,950 2024-04-24
Unclassified CRITICAL 9.1
CVE-2024-32954

Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.

Mitigation only
Fix from $2,300 2024-04-24
Unclassified CRITICAL 9.1
CVE-2024-32836

Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite …

Mitigation only
Fix from $2,300 2024-04-24
Forminator MEDIUM 5.3
CVE-2024-28890

Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote at…

Fix: 1.29.0+
Fix from $1,600 2024-04-23
Mozilocms MEDIUM 6.5
CVE-2024-29368

An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renam…

No fix yet
Fix from $1,600 2024-04-22
Dedecms CRITICAL 9.8
CVE-2024-29661

A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

Mitigation only
Fix from $2,300 2024-04-22
Avalanche HIGH 8.8
CVE-2024-23534

An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitra…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Library System CRITICAL 9.8
CVE-2024-3948

A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by this issue is some unknown func…

No fix yet
Fix from $2,300 2024-04-18
Jizhicms CRITICAL 9.8
CVE-2024-32161

jizhiCMS 2.5 suffers from a File upload vulnerability.

Mitigation only
Fix from $2,300 2024-04-17
Wp Poll Maker CRITICAL 9.9
CVE-2024-32514

Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll…

Fix: 3.5+
Fix from $2,300 2024-04-17
Unclassified HIGH 8.8
CVE-2024-31680

File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitr…

Mitigation only
Fix from $1,950 2024-04-17
Tourism Management System HIGH 8.1
CVE-2024-32256

Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When upda…

No fix yet
Fix from $1,950 2024-04-16
Tourism Management System HIGH 8.8
CVE-2024-32254

Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When cre…

No fix yet
Fix from $1,950 2024-04-16
Firefox CRITICAL 9.8
CVE-2024-3863

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other oper…

Fix: 115.10 / 115.10.0+
Fix from $2,300 2024-04-16
Codoforum HIGH 7.2
CVE-2020-22539

An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a craf…

No fix yet
Fix from $1,950 2024-04-15