Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Jpshop CRITICAL 9.8
CVE-2024-1263

A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function actionUpdate of the file /api/c…

Fix: after 1.5.02
Fix from $2,300 2024-02-06
Jpshop CRITICAL 9.8
CVE-2024-1260

A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controll…

Fix: after 1.5.02
Fix from $2,300 2024-02-06
Jpshop CRITICAL 9.8
CVE-2024-1261

A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function actionIndex of the file /api…

Fix: after 1.5.02
Fix from $2,300 2024-02-06
Agent Dvr HIGH 8.8
CVE-2024-22515

Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.

Mitigation only
Fix from $1,950 2024-02-06
Jpshop CRITICAL 9.8
CVE-2024-1259

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Fix: after 1.5.02
Fix from $2,300 2024-02-06
Smart S40 Firmware HIGH 7.2
CVE-2024-1253

A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126. Affected by this issue is s…

Fix: after 2024-01-26
Fix from $1,950 2024-02-06
Jsherp CRITICAL 9.8
CVE-2024-24000

jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz …

Mitigation only
Fix from $2,300 2024-02-06
Ai Engine HIGH 7.2
CVE-2024-0699

The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ…

Fix: after 2.1.4
Fix from $1,950 2024-02-05
Unlimited Addons For Wpbakery Page Builder HIGH 7.2
CVE-2023-6925

The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation …

Fix: after 1.0.42
Fix from $1,950 2024-02-05
Editorskit HIGH 7.2
CVE-2023-6635

The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'import_styles' function in ve…

Fix: after 1.40.3
Fix from $1,950 2024-02-05
File Manager HIGH 8.8
CVE-2023-6846EPSS 16%

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_fileman…

Fix: after 8.3.4
Fix from $1,950 2024-02-05
Mcms HIGH 8.8
CVE-2024-22567EPSS 18%

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

No fix yet
Fix from $1,950 2024-02-05
3dprint Lite CRITICAL 9.8
CVE-2021-4436EPSS 7%

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJ…

Fix: 1.9.1.5+
Fix from $2,300 2024-02-05
Cybermath CRITICAL 9.8
CVE-2023-6675

Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web S…

Mitigation only
Fix from $2,300 2024-02-02
Openbi CRITICAL 9.8
CVE-2024-1113

A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnity of the file /application/in…

Fix: after 1.0.8
Fix from $2,300 2024-01-31
Openbi CRITICAL 9.8
CVE-2024-1116

A vulnerability was found in openBI up to 1.0.8. It has been classified as critical. Affected is the function index of the file /application/plugins/…

Fix: after 1.0.8
Fix from $2,300 2024-01-31
Cms HIGH 7.2
CVE-2023-31505

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive i…

No fix yet
Fix from $1,950 2024-01-31
Database For Contact Form 7\, Wpforms\, Elementor Forms HIGH 7.2
CVE-2024-1069

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function…

Fix: 1.3.3+
Fix from $1,950 2024-01-31
Openbi CRITICAL 9.8
CVE-2024-1036

A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index…

Fix: after 1.0.8
Fix from $2,300 2024-01-30
Openbi CRITICAL 9.8
CVE-2024-1035

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /appl…

Fix: after 1.0.8
Fix from $2,300 2024-01-30
Openbi CRITICAL 9.8
CVE-2024-1034

A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/ind…

Fix: after 1.0.8
Fix from $2,300 2024-01-30
Facebook News Feed Like CRITICAL 9.8
CVE-2024-1027

A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is an unknown function of the co…

Mitigation only
Fix from $2,300 2024-01-30
Employee Management System HIGH 7.2
CVE-2024-1008

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an un…

No fix yet
Fix from $1,950 2024-01-29
Smart S210 Firmware CRITICAL 9.8
CVE-2024-0939EPSS 44%

A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown…

Fix: after 2024-01-17
Fix from $2,300 2024-01-26
B2b2c Multi Business CRITICAL 9.8
CVE-2024-0933

A vulnerability was found in Niushop B2B2C V5 and classified as critical. Affected by this issue is some unknown functionality of the file \app\model…

Mitigation only
Fix from $2,300 2024-01-26
Shopsite MEDIUM 6.1
CVE-2024-22550

An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code via uploa…

No fix yet
Fix from $1,600 2024-01-26
Mr2600 Firmware HIGH 8.8
CVE-2024-23630

An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on t…

Mitigation only
Fix from $1,950 2024-01-26
Leptoncms HIGH 7.2
CVE-2024-24399EPSS 16%

An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the ba…

No fix yet
Fix from $1,950 2024-01-25
Order Export \& Order Import For Woocommerce HIGH 7.2
CVE-2024-22135

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.This issue affects Order Expor…

Fix: 2.4.4+
Fix from $1,950 2024-01-24
Product Import Export For Woocommerce HIGH 7.2
CVE-2024-22152

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Ex…

Fix: 2.3.8+
Fix from $1,950 2024-01-24