Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Php Backend For Resumable.js HIGH 8.1
CVE-2023-52086

resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/fo…

Patch available
Fix from $1,950 2023-12-26
Dreamer Cms HIGH 8.8
CVE-2023-7091

A vulnerability was found in Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /upload/uplo…

No fix yet
Fix from $1,950 2023-12-24
Ex1200l Firmware CRITICAL 9.8
CVE-2023-51034

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.

No fix yet
Fix from $2,300 2023-12-22
Planning Analytics CRITICAL 9.8
CVE-2023-42017

IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By s…

Mitigation only
Fix from $2,300 2023-12-22
Online Notes Sharing System MEDIUM 5.4
CVE-2023-7054

A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing…

No fix yet
Fix from $1,600 2023-12-22
Automad MEDIUM 5.4
CVE-2023-7036

A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollection…

Fix: after 1.10.9
Fix from $1,600 2023-12-21
Drag And Drop Multiple File Upload For Woocommerce CRITICAL 9.8
CVE-2022-45377

Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue af…

Fix: 1.0.9+
Fix from $2,300 2023-12-21
Iptv Gateway MEDIUM 6.5
CVE-2023-7026

A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of th…

Fix: after 20231208
Fix from $1,600 2023-12-21
Corsa HIGH 8.8
CVE-2023-23970

Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5.

Fix: after 1.5
Fix from $1,950 2023-12-20
Zendrop CRITICAL 9.8
CVE-2023-25970

Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshippi…

Fix: 1.0.1+
Fix from $2,300 2023-12-20
User Submitted Posts CRITICAL 9.8
CVE-2023-45603

Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.Th…

Fix: after 20230902
Fix from $2,300 2023-12-20
Ultra HIGH 8.8
CVE-2023-46149

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

Fix: after 7.3.5
Fix from $1,950 2023-12-20
Slider Revolution HIGH 8.8
CVE-2023-47784

Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a thro…

Fix: after 6.6.15
Fix from $1,950 2023-12-20
Symbiostock HIGH 7.2
CVE-2023-49814

Unrestricted Upload of File with Dangerous Type vulnerability in Symbiostock symbiostock.This issue affects Symbiostock: from n/a through 6.0.0.

Fix: after 6.0.0
Fix from $1,950 2023-12-20
Unlimited Elements For Elementor MEDIUM 6.5
CVE-2023-31231

Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates…

Fix: 1.5.66+
Fix from $1,600 2023-12-20
Automatewoo HIGH 8.8
CVE-2023-33318

Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40.

Fix: after 4.9.40
Fix from $1,950 2023-12-20
Download Monitor HIGH 8.8
CVE-2023-34007

Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.

Fix: after 4.8.3
Fix from $1,950 2023-12-20
Export Import Menus HIGH 8.8
CVE-2023-34385

Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a…

Fix: after 1.8.0
Fix from $1,950 2023-12-20
Folders HIGH 7.2
CVE-2023-40204

Unrestricted Upload of File with Dangerous Type vulnerability in Premio Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, F…

Fix: after 2.9.2
Fix from $1,950 2023-12-20
Theme Demo Import HIGH 7.2
CVE-2023-28170

Unrestricted Upload of File with Dangerous Type vulnerability in Themely Theme Demo Import.This issue affects Theme Demo Import: from n/a through 1.1…

Fix: after 1.1.1
Fix from $1,950 2023-12-20
Olive One Click Demo Import HIGH 7.2
CVE-2023-29102

Unrestricted Upload of File with Dangerous Type vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Imp…

Fix: after 1.1.1
Fix from $1,950 2023-12-20
Jobwp CRITICAL 9.8
CVE-2023-29384

Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects Word…

Fix: after 2.0
Fix from $2,300 2023-12-20
Dropshipping \& Affiliation With Amazon HIGH 8.8
CVE-2023-31215

Unrestricted Upload of File with Dangerous Type vulnerability in AmaderCode Lab Dropshipping & Affiliation with Amazon.This issue affects Dropshippin…

Fix: after 2.1.2
Fix from $1,950 2023-12-20
Kakadu Sdk HIGH 7.5
CVE-2023-6562

JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server …

Fix: after 8.4
Fix from $1,950 2023-12-20
Mlflow HIGH 8.8
CVE-2023-6976

This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

Fix: 2.9.2+
Fix from $1,950 2023-12-20
Security Guardium Key Lifecycle Manager HIGH 8.8
CVE-2023-47706

IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.

Fix: 4.2.0.2+
Fix from $1,950 2023-12-20
Avalanche CRITICAL 9.8
CVE-2023-46263EPSS 82%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve…

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46264EPSS 90%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve…

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Vrm360 HIGH 8.8
CVE-2023-4311

The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

Fix: after 1.2.1
Fix from $1,950 2023-12-18
Stupid Simple Cms CRITICAL 9.8
CVE-2023-6902

A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the f…

Fix: after 1.2.4
Fix from $2,300 2023-12-17