Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Essential Real Estate HIGH 8.8
CVE-2023-6140

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentaril…

Fix: 4.4.0+
Fix from $1,950 2024-01-08
Ni Purchase Order\(po\) For Woocommerce HIGH 7.2
CVE-2023-5957

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, a…

Fix: after 1.2.1
Fix from $1,950 2024-01-08
Smart S150 Firmware CRITICAL 9.8
CVE-2024-0300EPSS 6%

A vulnerability was found in Byzoro Smart S150 Management Platform up to 20240101. It has been rated as critical. Affected by this issue is some unkn…

Fix: after 2024-01-01
Fix from $2,300 2024-01-08
Dedecms CRITICAL 9.8
CVE-2023-7212

A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the com…

Fix: after 5.7.112
Fix from $2,300 2024-01-07
Js Help Desk CRITICAL 9.8
CVE-2022-46839

Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS He…

Fix: after 2.7.1
Fix from $2,300 2024-01-05
Class.upload.php MEDIUM 5.4
CVE-2023-6551

As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default conf…

Mitigation only
Fix from $1,600 2024-01-04
Online Notice Board System HIGH 8.8
CVE-2023-50760

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allo…

No fix yet
Fix from $1,950 2024-01-04
Gl Mt1300 Firmware HIGH 7.2
CVE-2023-50922

An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploadi…

No fix yet
Fix from $1,950 2024-01-03
Dryice Myxalytics CRITICAL 9.8
CVE-2023-45724

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file with…

Mitigation only
Fix from $2,300 2024-01-03
Internet Banking System CRITICAL 9.8
CVE-2024-0194

A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown pro…

No fix yet
Fix from $2,300 2024-01-02
Rrj Nueva Ecija Engineer Online Portal MEDIUM 5.4
CVE-2024-0192

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unkno…

No fix yet
Fix from $1,600 2024-01-02
Rrj Nueva Ecija Engineer Online Portal HIGH 8.8
CVE-2024-0185

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been rated as critical. This issue affects some unknown processing of…

No fix yet
Fix from $1,950 2024-01-02
Dedebiz HIGH 7.2
CVE-2023-7181

A vulnerability was found in Muyun DedeBIZ up to 6.2.12 and classified as critical. Affected by this issue is some unknown functionality of the compo…

Fix: after 6.2.12
Fix from $1,950 2023-12-30
Bertha Ai CRITICAL 9.8
CVE-2023-51419

Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and Chrome.This issue affects BE…

Fix: after 1.11.10.7
Fix from $2,300 2023-12-29
Verge3d HIGH 8.8
CVE-2023-51421

Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishin…

Fix: after 4.5.2
Fix from $1,950 2023-12-29
Download Rencontre Dating Site CRITICAL 9.8
CVE-2023-51468

Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site…

Fix: after 3.10.1
Fix from $2,300 2023-12-29
Terraclassifieds CRITICAL 9.8
CVE-2023-51473

Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassi…

Fix: after 2.0.3
Fix from $2,300 2023-12-29
Wp Mlm Unilevel CRITICAL 9.8
CVE-2023-51475

Unrestricted Upload of File with Dangerous Type vulnerability in IOSS WP MLM SOFTWARE PLUGIN.This issue affects WP MLM SOFTWARE PLUGIN: from n/a thro…

Fix: after 4.0
Fix from $2,300 2023-12-29
Wp Mail Log HIGH 8.8
CVE-2023-51410

Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.

Fix: after 1.1.2
Fix from $1,950 2023-12-29
Frontend Admin CRITICAL 9.8
CVE-2023-51411

Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by Dyna…

Fix: after 3.18.3
Fix from $2,300 2023-12-29
Piotnet Forms CRITICAL 9.8
CVE-2023-51412

Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.

Fix: after 1.0.25
Fix from $2,300 2023-12-29
Jvm Gutenberg Rich Text Icons HIGH 8.8
CVE-2023-51417

Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Ri…

Fix: after 1.2.3
Fix from $1,950 2023-12-29
Masterlab CRITICAL 9.8
CVE-2023-7159

A vulnerability was found in gopeak MasterLab up to 3.3.10. It has been declared as critical. Affected by this vulnerability is the function add/upda…

Fix: after 3.3.10
Fix from $2,300 2023-12-29
Chic Beauty Salon HIGH 8.8
CVE-2023-7150

A vulnerability classified as critical was found in Campcodes Chic Beauty Salon 20230703. Affected by this vulnerability is an unknown functionality …

Mitigation only
Fix from $1,950 2023-12-29
Masterlab CRITICAL 9.8
CVE-2023-7147

A vulnerability, which was classified as critical, was found in gopeak MasterLab up to 3.3.10. Affected is the function base64ImageContent of the fil…

Fix: after 3.3.10
Fix from $2,300 2023-12-29
Zzcms CRITICAL 9.8
CVE-2023-50104

ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and …

No fix yet
Fix from $2,300 2023-12-29
Textpattern HIGH 8.8
CVE-2023-50038

There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.

No fix yet
Fix from $1,950 2023-12-28
Jizhicms HIGH 8.8
CVE-2023-50692

File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the downl…

No fix yet
Fix from $1,950 2023-12-28
Rtmedia HIGH 8.8
CVE-2023-5931

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers …

Fix: 4.6.16+
Fix from $1,950 2023-12-26
Wp Mail Log HIGH 8.8
CVE-2023-5673

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to u…

Fix: 1.1.3+
Fix from $1,950 2023-12-26