Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Bookingpress HIGH 7.2
CVE-2023-6219

The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload…

Fix: after 1.0.76
Fix from $1,950 2023-11-28
Sentrifugo HIGH 8.8
CVE-2023-29770

In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering.

No fix yet
Fix from $1,950 2023-11-28
Asgaros Forum CRITICAL 9.8
CVE-2023-5604

The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configu…

Fix: 2.7.1+
Fix from $2,300 2023-11-27
Udp CRITICAL 9.8
CVE-2023-41998EPSS 15%

Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows …

Fix: 9.2+
Fix from $2,300 2023-11-27
Video Surveillance Management System HIGH 8.8
CVE-2023-6308

A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by th…

No fix yet
Fix from $1,950 2023-11-27
Smart S80 Firmware CRITICAL 9.8
CVE-2023-6274

A vulnerability was found in Byzoro Smart S80 up to 20231108. It has been declared as critical. Affected by this vulnerability is an unknown function…

Fix: after 2023-11-08
Fix from $2,300 2023-11-24
Pandora Fms HIGH 8.8
CVE-2023-41812

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. …

Fix: 774+
Fix from $1,950 2023-11-23
Pandora Fms HIGH 8.8
CVE-2023-41788

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. …

Fix: 774+
Fix from $1,950 2023-11-23
Drag And Drop Multiple File Upload Contact Form 7 CRITICAL 9.8
CVE-2023-5822

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type va…

Fix: after 1.3.7.3
Fix from $2,300 2023-11-22
Paid Memberships Pro HIGH 8.8
CVE-2023-6187EPSS 52%

The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalex…

Fix: after 2.12.3
Fix from $1,950 2023-11-18
Expresscluster X HIGH 8.8
CVE-2023-39548

CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSaf…

Patch available
Fix from $1,950 2023-11-17
Opensupports CRITICAL 9.8
CVE-2023-48031

OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restr…

No fix yet
Fix from $2,300 2023-11-17
Statamic HIGH 8.8
CVE-2023-48217

Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…

Fix: 3.4.14 / 4.34.0+
Fix from $1,950 2023-11-14
Suitecrm MEDIUM 5.4
CVE-2023-6127

Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

Fix: 7.12.14+
Fix from $1,600 2023-11-14
Guest Entries HIGH 8.8
CVE-2023-47621

Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In affected versions the file uplo…

Fix: 3.1.3+
Fix from $1,950 2023-11-13
Maiwei Safety Production Control Platform CRITICAL 9.8
CVE-2023-6102

A vulnerability, which was classified as problematic, was found in Maiwei Safety Production Control Platform 4.1. Affected is an unknown function of …

Mitigation only
Fix from $2,300 2023-11-13
Statamic CRITICAL 9.8
CVE-2023-47129

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload fi…

Fix: 3.4.13 / 4.33.0+
Fix from $2,300 2023-11-10
Ws Ftp Server HIGH 8.8
CVE-2023-42659

In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has …

Fix: 8.7.6 / 8.8.4+
Fix from $1,950 2023-11-07
Remote Clinic HIGH 8.8
CVE-2023-33480

RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create ad…

No fix yet
Fix from $1,950 2023-11-07
Woocommerce Ninja Forms Product Add Ons CRITICAL 9.8
CVE-2023-5601

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated use…

Fix: 1.7.1+
Fix from $2,300 2023-11-06
Avalanche HIGH 7.8
CVE-2023-41725

Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
Vitals Enterprise Social Platform HIGH 8.8
CVE-2023-41357

Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during fi…

Fix: after 6.1
Fix from $1,950 2023-11-03
Company Website Cms HIGH 7.2
CVE-2023-5919

A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionali…

No fix yet
Fix from $1,950 2023-11-02
Glpi CRITICAL 9.8
CVE-2023-42802

GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation …

Fix: 10.0.10+
Fix from $2,300 2023-11-02
Icons Font Loader HIGH 7.2
CVE-2023-5860

The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all …

Fix: 1.1.3+
Fix from $1,950 2023-11-02
Hadsky HIGH 8.8
CVE-2023-46428

An arbitrary file upload vulnerability in HadSky v7.12.10 allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $1,950 2023-11-01
Identity Services Engine HIGH 7.2
CVE-2023-20196

Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vuln…

Mitigation only
Fix from $1,950 2023-11-01
Identity Services Engine HIGH 7.2
CVE-2023-20195

Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vuln…

Mitigation only
Fix from $1,950 2023-11-01
Bitrix24 HIGH 8.0
CVE-2023-1720

Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's bro…

No fix yet
Fix from $1,950 2023-11-01
Bitrix24 HIGH 8.8
CVE-2023-1713

Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote…

No fix yet
Fix from $1,950 2023-11-01