Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Membership Management System HIGH 7.2
CVE-2024-1819

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the comp…

No fix yet
Fix from $1,950 2024-02-23
S Museum CRITICAL 9.8
CVE-2024-25802

SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content.

Mitigation only
Fix from $2,300 2024-02-22
Answer CRITICAL 9.1
CVE-2024-22393

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack b…

Fix: 1.2.5+
Fix from $2,300 2024-02-22
Ediscovery Platform HIGH 7.2
CVE-2024-27283

A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload potentially malicious files to …

Fix: 10.2.5+
Fix from $1,950 2024-02-22
S Museum MEDIUM 6.1
CVE-2024-25801

SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the conten…

Mitigation only
Fix from $1,600 2024-02-22
Pmb HIGH 7.2
CVE-2023-52154

File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files.

Fix: after 7.4.7
Fix from $1,950 2024-02-21
Novel Plus CRITICAL 9.8
CVE-2024-25274

An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploa…

Mitigation only
Fix from $2,300 2024-02-20
Timo CRITICAL 9.8
CVE-2024-22824

An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

No fix yet
Fix from $2,300 2024-02-20
Suitecrm HIGH 8.8
CVE-2024-1644

Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

No fix yet
Fix from $1,950 2024-02-20
Misskey HIGH 8.8
CVE-2024-25636

Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Str…

Fix: 2024.2.0+
Fix from $1,950 2024-02-19
Mastodon HIGH 7.7
CVE-2024-25623

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote…

Fix: 3.5.19 / 4.0.15+
Fix from $1,950 2024-02-19
Trusteer Android Sdk For Mobile CRITICAL 9.8
CVE-2022-42443

An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploadi…

Fix: 5.7+
Fix from $2,300 2024-02-17
Recoverpoint For Virtual Machines CRITICAL 9.8
CVE-2024-22426

Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potent…

Mitigation only
Fix from $2,300 2024-02-16
Csz Cms CRITICAL 9.8
CVE-2024-25414

An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip fil…

No fix yet
Fix from $2,300 2024-02-16
Sinec Nms HIGH 8.8
CVE-2024-23811

A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP.…

Fix: 2.0+
Fix from $1,950 2024-02-13
Gambio CRITICAL 9.8
CVE-2024-23759EPSS 48%

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/Add…

No fix yet
Fix from $2,300 2024-02-12
Gambio HIGH 7.8
CVE-2024-23762

Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted …

No fix yet
Fix from $1,950 2024-02-12
Solr HIGH 8.8
CVE-2023-50386EPSS 84%

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co…

Fix: 8.11.3 / 9.4.1+
Fix from $1,950 2024-02-09
Misp CRITICAL 9.8
CVE-2024-25674

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

Fix: 2.4.184+
Fix from $2,300 2024-02-09
Pichome CRITICAL 9.8
CVE-2024-24393

File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.

No fix yet
Fix from $2,300 2024-02-08
October HIGH 7.8
CVE-2023-25365

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

No fix yet
Fix from $1,950 2024-02-08
Unify Openscape Xpressions Webassistant HIGH 8.8
CVE-2023-40265

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution v…

Fix: 7r1_fr5_hf42_p911+
Fix from $1,950 2024-02-08
Zentao CRITICAL 9.8
CVE-2024-24202

An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows atta…

No fix yet
Fix from $2,300 2024-02-08
Novel Plus CRITICAL 9.8
CVE-2024-24024

An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). A…

Fix: after 4.2.0
Fix from $2,300 2024-02-08
Novel Plus CRITICAL 9.8
CVE-2024-24025

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attack…

Fix: after 4.2.0
Fix from $2,300 2024-02-08
Novel Plus CRITICAL 9.8
CVE-2024-24026

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadI…

Fix: after 4.2.0
Fix from $2,300 2024-02-08
E Sic Livre HIGH 8.8
CVE-2024-24350

File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filte…

Fix: after 2.0
Fix from $1,950 2024-02-08
Restaurant Pos System CRITICAL 9.8
CVE-2024-1268

A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_…

Mitigation only
Fix from $2,300 2024-02-07
Jpshop CRITICAL 9.8
CVE-2024-1264

A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate…

Fix: after 1.5.02
Fix from $2,300 2024-02-07
Jpshop CRITICAL 9.8
CVE-2024-1262

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the…

Fix: after 1.5.02
Fix from $2,300 2024-02-06