Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Barcode Scanner And Inventory Manager CRITICAL 9.8
CVE-2023-52221

Unrestricted Upload of File with Dangerous Type vulnerability in UkrSolution Barcode Scanner and Inventory manager.This issue affects Barcode Scanner…

Fix: 1.5.2+
Fix from $2,300 2024-01-24
Apex Central HIGH 8.8
CVE-2023-52324

An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installatio…

Mitigation only
Fix from $1,950 2024-01-23
A Blog Cms HIGH 8.8
CVE-2024-23180

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ve…

Fix: 2.10.50 / 2.11.58+
Fix from $1,950 2024-01-23
Online Admission System CRITICAL 9.8
CVE-2024-0783

A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the…

No fix yet
Fix from $2,300 2024-01-22
Dedecms HIGH 8.8
CVE-2024-22895

DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.

No fix yet
Fix from $1,950 2024-01-22
Yonbip CRITICAL 9.8
CVE-2023-51924

An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrar…

Mitigation only
Fix from $2,300 2024-01-20
Yonbip CRITICAL 9.8
CVE-2023-51925

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attack…

Mitigation only
Fix from $2,300 2024-01-20
Yonbip CRITICAL 9.8
CVE-2023-51928

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attack…

Mitigation only
Fix from $2,300 2024-01-20
Terminal Security System CRITICAL 9.8
CVE-2021-31314

File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.

No fix yet
Fix from $2,300 2024-01-20
Write Back Manager CRITICAL 9.8
CVE-2023-27168

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

No fix yet
Fix from $2,300 2024-01-19
Openedge CRITICAL 9.9
CVE-2023-40051

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…

Fix: 11.7.18 / 12.2.13+
Fix from $2,300 2024-01-18
Yunyou Cms CRITICAL 9.8
CVE-2024-0648

A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/c…

Fix: after 2.2.6
Fix from $2,300 2024-01-17
Unity Connection CRITICAL 9.8
CVE-2024-20272

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary f…

Fix: 12.5.1.19017-4 / 14.0.1.14006-5+
Fix from $2,300 2024-01-17
Live Encoder CRITICAL 9.8
CVE-2024-0643

Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker…

Mitigation only
Fix from $2,300 2024-01-17
My Account Page Editor HIGH 8.8
CVE-2023-4536

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such…

Fix: 1.3.2+
Fix from $1,950 2024-01-16
Theme Demo Import HIGH 7.2
CVE-2022-1538

Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary …

Fix: 1.1.1+
Fix from $1,950 2024-01-16
Traccar CRITICAL 9.8
CVE-2023-50729

Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows…

Fix: 5.11+
Fix from $2,300 2024-01-15
Austin CRITICAL 9.8
CVE-2024-0505

A vulnerability was found in ZhongFuCheng3y Austin 1.0 and classified as critical. This issue affects the function getFile of the file com/java3y/aus…

No fix yet
Fix from $2,300 2024-01-13
Fighting Cock Information System CRITICAL 9.8
CVE-2024-0468

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this vulnerability is an…

Mitigation only
Fix from $2,300 2024-01-12
Ujcms MEDIUM 5.4
CVE-2023-51806

File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.

No fix yet
Fix from $1,600 2024-01-12
Pmb HIGH 7.2
CVE-2023-46474EPSS 21%

File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to t…

Fix: after 7.5.3
Fix from $1,950 2024-01-11
Customer Reviews For Woocommerce HIGH 8.8
CVE-2023-6979

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_im…

Fix: after 5.38.9
Fix from $1,950 2024-01-11
Greenshift HIGH 7.2
CVE-2023-6636

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation o…

Fix: after 7.6.2
Fix from $1,950 2024-01-11
Import Export Wordpress Users HIGH 7.2
CVE-2023-6558

The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on th…

Fix: after 2.4.8
Fix from $1,950 2024-01-11
Mw Wp Form CRITICAL 9.8
CVE-2023-6316

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' fun…

Fix: after 5.0.1
Fix from $2,300 2024-01-11
Piotnet Forms CRITICAL 9.8
CVE-2023-6220

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_for…

Fix: after 1.0.26
Fix from $2,300 2024-01-11
Avideo HIGH 8.8
CVE-2023-49715

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. …

No fix yet
Fix from $1,950 2024-01-10
Hospital Management System CRITICAL 9.8
CVE-2020-26629

A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker …

No fix yet
Fix from $2,300 2024-01-10
Likeshop CRITICAL 9.8
CVE-2024-0352EPSS 73%

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage …

Fix: after 2.5.7.20210311
Fix from $2,300 2024-01-09
Stud.ip CRITICAL 9.0
CVE-2023-50982

Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do n…

Fix: 5.0.9 / 5.1.7+
Fix from $2,300 2024-01-08