Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Magicflue CRITICAL 9.8
CVE-2024-28441

File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid par…

Fix: after 7.0
Fix from $2,300 2024-03-22
Zippy HIGH 8.8
CVE-2024-27964

Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.

Fix: 1.6.10+
Fix from $1,950 2024-03-21
Complete E Commerce Site HIGH 8.8
CVE-2024-2754

A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /ad…

No fix yet
Fix from $1,950 2024-03-21
Misp CRITICAL 9.8
CVE-2024-29859

In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

Fix: 2.4.187+
Fix from $2,300 2024-03-21
Grav HIGH 8.8
CVE-2024-27923

Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient …

Fix: 1.7.43+
Fix from $1,950 2024-03-21
Geoserver HIGH 7.2
CVE-2023-51444

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerabili…

Fix: 2.23.4+
Fix from $1,950 2024-03-20
Online Discussion Forum Site CRITICAL 9.8
CVE-2024-2690

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of …

No fix yet
Fix from $2,300 2024-03-20
Wemanage HIGH 8.8
CVE-2024-1205

The Management App for WooCommerce – Order notifications, Order management, Lead management, Uptime Monitoring plugin for WordPress is vulnerable to …

Fix: 1.2.3+
Fix from $1,950 2024-03-20
Tourfic HIGH 8.8
CVE-2024-29135

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15.

Fix: 2.11.16+
Fix from $1,950 2024-03-19
Unclassified CRITICAL 9.0
CVE-2024-2636

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/c…

Mitigation only
Fix from $2,300 2024-03-19
File Manager App CRITICAL 9.8
CVE-2024-2604

A vulnerability was found in SourceCodester File Manager App 1.0. It has been declared as critical. This vulnerability affects unknown code of the fi…

Mitigation only
Fix from $2,300 2024-03-18
Amss\+\+ HIGH 8.8
CVE-2024-2599

File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE …

Mitigation only
Fix from $1,950 2024-03-18
Pie Register CRITICAL 9.8
CVE-2024-27957

Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.

Fix: 3.8.3.3+
Fix from $2,300 2024-03-17
Pandax CRITICAL 9.8
CVE-2024-2565

A vulnerability was found in PandaXGO PandaX up to 20240310. It has been classified as critical. Affected is an unknown function of the file /apps/sy…

Fix: after 2024-03-10
Fix from $2,300 2024-03-17
74cms HIGH 8.8
CVE-2024-2561EPSS 6%

A vulnerability, which was classified as critical, has been found in 74CMS 3.28.0. Affected by this issue is the function sendCompanyLogo of the file…

No fix yet
Fix from $1,950 2024-03-17
Online College Event Hall Reservation System HIGH 8.8
CVE-2024-2531

A vulnerability classified as critical has been found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. Affected is an unknown function…

Mitigation only
Fix from $1,950 2024-03-16
Online College Event Hall Reservation System HIGH 8.8
CVE-2024-2529

A vulnerability was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. It has been declared as critical. This vulnerability affect…

Mitigation only
Fix from $1,950 2024-03-16
Eyoucms CRITICAL 9.8
CVE-2023-42286

There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands th…

No fix yet
Fix from $2,300 2024-03-14
Openeclass CRITICAL 9.1
CVE-2024-26503

Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload…

Fix: after 3.15
Fix from $2,300 2024-03-14
Airflow Diagrams CRITICAL 9.8
CVE-2024-28423

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability al…

Mitigation only
Fix from $2,300 2024-03-14
Greykite HIGH 7.5
CVE-2024-28425

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnera…

Mitigation only
Fix from $1,950 2024-03-14
Webedition Cms MEDIUM 6.5
CVE-2024-28418

Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

No fix yet
Fix from $1,600 2024-03-14
Student Enrollment CRITICAL 9.8
CVE-2023-41505

An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute ar…

Mitigation only
Fix from $2,300 2024-03-13
Udp HIGH 8.8
CVE-2024-0800

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.ser…

No fix yet
Fix from $1,950 2024-03-13
Brizy HIGH 8.8
CVE-2024-1311

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function…

Fix: 2.4.41+
Fix from $1,950 2024-03-13
Gacjie Server CRITICAL 9.8
CVE-2024-2406

A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/contr…

Fix: after 1.0
Fix from $2,300 2024-03-12
Unclassified MEDIUM 6.8
CVE-2023-30968

One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to by…

Mitigation only
Fix from $1,600 2024-03-12
Cms Made Simple HIGH 8.8
CVE-2024-1527

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the se…

Mitigation only
Fix from $1,950 2024-03-12
Employee Management System CRITICAL 9.8
CVE-2024-2394

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown fun…

Mitigation only
Fix from $2,300 2024-03-12
Charx Sec 3000 Firmware MEDIUM 5.3
CVE-2024-25994

An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write …

Fix: 1.5.1+
Fix from $1,600 2024-03-12