Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified MEDIUM 6.3
CVE-2024-3804

A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processin…

Mitigation only
Fix from $1,600 2024-04-15
Unclassified MEDIUM 6.3
CVE-2024-3803

A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Publi…

Mitigation only
Fix from $1,600 2024-04-15
Qbibot HIGH 7.2
CVE-2024-3778

The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privileg…

Mitigation only
Fix from $1,950 2024-04-15
Nginxwebui HIGH 7.5
CVE-2024-3736

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function uplo…

Fix: 4.2.4+
Fix from $1,950 2024-04-13
Opengnsys HIGH 8.8
CVE-2024-3705

Unrestricted file upload vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to send a POST request t…

Mitigation only
Fix from $1,950 2024-04-12
Ai Engine CRITICAL 9.8
CVE-2023-51409EPSS 63%

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:…

Fix: 1.9.99+
Fix from $2,300 2024-04-12
Otter Blocks MEDIUM 5.4
CVE-2024-3344

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV…

Fix: 2.6.9+
Fix from $1,600 2024-04-11
Traccar CRITICAL 9.6
CVE-2024-31214EPSS 18%

Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload…

Fix: after 5.12
Fix from $2,300 2024-04-10
Qdrant CRITICAL 9.8
CVE-2024-2221

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint…

Patch available
Fix from $2,300 2024-04-10
Unclassified HIGH 8.5
CVE-2024-24809EPSS 54%

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous …

Patch available
Fix from $1,950 2024-04-10
Unclassified MEDIUM 6.4
CVE-2024-2334

The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up …

Mitigation only
Fix from $1,600 2024-04-09
Envialosimple HIGH 8.8
CVE-2024-2125

The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin…

Fix: 2.4+
Fix from $1,950 2024-04-09
Unclassified MEDIUM 6.5
CVE-2024-31454

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which is desig…

Patch available
Fix from $1,600 2024-04-09
Unclassified MEDIUM 6.5
CVE-2024-31453

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which allows u…

Patch available
Fix from $1,600 2024-04-09
Prison Management System HIGH 7.2
CVE-2024-3436

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code o…

No fix yet
Fix from $1,950 2024-04-08
Prison Management System HIGH 7.2
CVE-2024-3437

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing o…

No fix yet
Fix from $1,950 2024-04-08
Unclassified CRITICAL 9.1
CVE-2024-31345

Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

Mitigation only
Fix from $2,300 2024-04-07
Unclassified CRITICAL 9.9
CVE-2024-31286

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album …

Mitigation only
Fix from $2,300 2024-04-07
Unclassified HIGH 7.2
CVE-2024-31292

Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: f…

Mitigation only
Fix from $1,950 2024-04-07
Church Admin HIGH 8.8
CVE-2024-31280

Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a throu…

Fix: 4.1.6+
Fix from $1,950 2024-04-07
Car Rental HIGH 8.8
CVE-2024-3369

A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionali…

No fix yet
Fix from $1,950 2024-04-06
WordPress HIGH 8.8
CVE-2024-31210

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an …

Fix: 4.1.40 / 4.2.37+
Fix from $1,950 2024-04-04
Projeqtor HIGH 8.8
CVE-2024-29387

projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.

Fix: after 11.2.0
Fix from $1,950 2024-04-04
Unclassified MEDIUM 6.5
CVE-2024-28520

File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to…

Mitigation only
Fix from $1,600 2024-04-04
Bookingpress HIGH 7.2
CVE-2024-3022

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_up…

Fix: after 1.0.87
Fix from $1,950 2024-04-04
Multiple Page Generator HIGH 7.2
CVE-2024-27951

Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Se…

Fix: 3.4.1+
Fix from $1,950 2024-04-03
Semcms CRITICAL 9.8
CVE-2024-31012

An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via…

No fix yet
Fix from $2,300 2024-04-03
Leptoncms HIGH 8.8
CVE-2024-29514

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

No fix yet
Fix from $1,950 2024-04-02
Image Accordion Gallery App MEDIUM 6.3
CVE-2024-3129

A vulnerability was found in SourceCodester Image Accordion Gallery App 1.0. It has been classified as critical. This affects an unknown part of the …

No fix yet
Fix from $1,600 2024-04-01
Unclassified HIGH 7.5
CVE-2024-30533

Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a b…

Mitigation only
Fix from $1,950 2024-03-31