Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Online Bookstore Website CRITICAL 9.8
CVE-2024-2268

A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0. It has been classified as critical. Affected is an unknown function of the fil…

Mitigation only
Fix from $2,300 2024-03-07
Booster For Woocommerce HIGH 8.8
CVE-2024-1986

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_…

Fix: 7.1.8+
Fix from $1,950 2024-03-07
Unclassified HIGH 7.7
CVE-2024-27733

File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/use…

Mitigation only
Fix from $1,950 2024-03-07
Imx6 HIGH 8.8
CVE-2023-45599

A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allow…

Fix: 1.0.7-2+
Fix from $1,950 2024-03-05
Imx6 HIGH 8.8
CVE-2023-45595

A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a r…

Fix: 1.0.7-2+
Fix from $1,950 2024-03-05
Online Mobile Store Management System HIGH 8.8
CVE-2024-2148

A vulnerability classified as critical has been found in SourceCodester Online Mobile Management Store 1.0. This affects an unknown part of the file …

No fix yet
Fix from $1,950 2024-03-03
Petrol Pump Management CRITICAL 9.8
CVE-2024-27747EPSS 24%

File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Ima…

No fix yet
Fix from $2,300 2024-03-01
Petrol Pump Management HIGH 7.2
CVE-2024-2059

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected by this issue is some unknow…

Mitigation only
Fix from $1,950 2024-03-01
Petrol Pump Management HIGH 7.2
CVE-2024-2058

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been declared as critical. Affected by this vulnerability is …

Mitigation only
Fix from $1,950 2024-03-01
Laragon CRITICAL 9.8
CVE-2024-0864

Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input v…

Fix: 7.0.0+
Fix from $2,300 2024-02-29
Mollie Payments For Woocommerce HIGH 7.2
CVE-2023-6090

Unrestricted Upload of File with Dangerous Type vulnerability in Mollie Mollie Payments for WooCommerce.This issue affects Mollie Payments for WooCom…

Fix: 7.3.12+
Fix from $1,950 2024-02-29
Avada HIGH 8.8
CVE-2024-1468

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validati…

Fix: 7.11.5+
Fix from $1,950 2024-02-29
Datacube3 HIGH 8.8
CVE-2024-25832EPSS 13%

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous ty…

No fix yet
Fix from $1,950 2024-02-29
Ofbiz MEDIUM 5.3
CVE-2024-23946

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $1,600 2024-02-29
Libming MEDIUM 6.5
CVE-2024-24146

A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

No fix yet
Fix from $1,600 2024-02-29
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25921

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that c…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-29
Membership Management System HIGH 8.8
CVE-2024-25869EPSS 19%

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code v…

No fix yet
Fix from $1,950 2024-02-28
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-25922

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that c…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-28
Product Catalog \(csv\, Excel\) Import CRITICAL 9.1
CVE-2024-25846

In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with…

Fix: after 6.7.0
Fix from $2,300 2024-02-27
Ctcms HIGH 8.1
CVE-2024-1925

A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controller…

Mitigation only
Fix from $1,950 2024-02-27
Lightpicture CRITICAL 9.8
CVE-2024-1921

A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/cont…

Fix: after 1.2.2
Fix from $2,300 2024-02-27
Smart S42 Management Platform CRITICAL 9.8
CVE-2024-1918

A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affected by this vulnerability is a…

Fix: after 20240219
Fix from $2,300 2024-02-27
Student Enrollment CRITICAL 9.8
CVE-2023-41506

An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to ex…

Mitigation only
Fix from $2,300 2024-02-27
Wp Media Folder HIGH 8.8
CVE-2024-25909

Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.…

Fix: 5.7.3+
Fix from $1,950 2024-02-26
Moveto CRITICAL 9.8
CVE-2024-25913

Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

Fix: after 6.2
Fix from $2,300 2024-02-26
Easy Checkout Field Editor CRITICAL 9.8
CVE-2024-25925

Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affect…

Fix: 3.5.13+
Fix from $2,300 2024-02-26
Icons Font Loader HIGH 7.2
CVE-2024-24714

Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a throug…

Fix: 1.1.5+
Fix from $1,950 2024-02-26
Flusity MEDIUM 6.5
CVE-2024-25410

flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.

Patch available
Fix from $1,600 2024-02-26
Complaint Management System HIGH 8.8
CVE-2024-1875

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affects some unknown processing of…

No fix yet
Fix from $1,950 2024-02-26
Membership Management System HIGH 7.2
CVE-2024-1818

A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this issue is some unknown functional…

No fix yet
Fix from $1,950 2024-02-23