Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Forestblog CRITICAL 9.8
CVE-2023-6887

A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img…

Fix: after 2022-06-30
Fix from $2,300 2023-12-17
Kodexplorer CRITICAL 9.8
CVE-2023-6850

A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the fi…

Fix: 4.52.01+
Fix from $2,300 2023-12-16
Webitr Attendance System HIGH 8.8
CVE-2023-48394

Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote at…

Mitigation only
Fix from $1,950 2023-12-15
E2pdf HIGH 7.2
CVE-2023-6826

The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in ve…

Fix: after 1.20.25
Fix from $1,950 2023-12-15
Essential Real Estate HIGH 8.8
CVE-2023-6827

The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFon…

Fix: after 4.3.5
Fix from $1,950 2023-12-15
Cws Collaborative Development Platform CRITICAL 9.8
CVE-2023-48376

SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unau…

Mitigation only
Fix from $2,300 2023-12-15
Omicard Edm CRITICAL 9.8
CVE-2023-48371

ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit th…

Mitigation only
Fix from $2,300 2023-12-15
Pluck HIGH 8.8
CVE-2023-50564EPSS 29%

An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via …

No fix yet
Fix from $1,950 2023-12-14
Repox CRITICAL 9.8
CVE-2023-6723

An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfi…

Mitigation only
Fix from $2,300 2023-12-13
Student Information System HIGH 8.8
CVE-2023-4122

Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authe…

No fix yet
Fix from $1,950 2023-12-07
Smart S210 Firmware HIGH 8.8
CVE-2023-6576

A vulnerability was found in Byzoro S210 up to 20231123. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/…

Fix: after 2023-11-21
Fix from $1,950 2023-12-07
Smart S20 Firmware HIGH 8.8
CVE-2023-6574

A vulnerability was found in Byzoro Smart S20 up to 20231120 and classified as critical. Affected by this issue is some unknown functionality of the …

Fix: after 2023-11-20
Fix from $1,950 2023-12-07
Aptio V HIGH 7.8
CVE-2023-39538

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A s…

Mitigation only
Fix from $1,950 2023-12-06
Aptio V HIGH 7.8
CVE-2023-39539

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A s…

Mitigation only
Fix from $1,950 2023-12-06
Xinhu CRITICAL 9.8
CVE-2023-48930

xinhu xinhuoa 2.2.1 contains a File upload vulnerability.

No fix yet
Fix from $2,300 2023-12-06
Aleos MEDIUM 5.4
CVE-2023-40460

The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authentica…

Fix: after 4.16.0
Fix from $1,600 2023-12-04
Welcart E Commerce HIGH 8.8
CVE-2023-5953

The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJ…

Fix: 2.9.5+
Fix from $1,950 2023-12-04
Thinkadmin HIGH 8.8
CVE-2023-48965

An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malici…

No fix yet
Fix from $1,950 2023-12-04
Thinkadmin HIGH 8.8
CVE-2023-48966

An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a…

No fix yet
Fix from $1,950 2023-12-04
Arslansoft Education Portal CRITICAL 9.8
CVE-2023-5636

Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. This issue affects Education …

Fix: 1.1+
Fix from $2,300 2023-12-01
Arslansoft Education Portal HIGH 7.5
CVE-2023-5637

Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Read Sensitive Strings Within an Executable. Thi…

Fix: 1.1+
Fix from $1,950 2023-12-01
Contact Form 7 HIGH 7.2
CVE-2023-6449

The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function a…

Fix: 5.8.4+
Fix from $1,950 2023-12-01
Espocrm HIGH 7.2
CVE-2023-5966

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, …

Fix: after 7.5.2
Fix from $1,950 2023-11-30
Espocrm HIGH 7.2
CVE-2023-5965

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could le…

Fix: after 7.5.2
Fix from $1,950 2023-11-30
Microweber HIGH 8.8
CVE-2023-49052

File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i…

Patch available
Fix from $1,950 2023-11-30
Chamilo Lms HIGH 8.8
CVE-2023-4226

Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remo…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4224

Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain r…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4225

Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4223

Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms MEDIUM 6.1
CVE-2023-4220EPSS 76%

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows…

Fix: after 1.11.24
Fix from $1,600 2023-11-28