Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Automate HIGH 8.8
CVE-2023-40050

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with malicious…

Fix: after 4.10.29
Fix from $1,950 2023-10-31
Royal Elementor Addons CRITICAL 9.8
CVE-2023-5360EPSS 82%

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated …

Fix: 1.3.79+
Fix from $2,300 2023-10-31
Bigbluebutton HIGH 8.8
CVE-2023-42803

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the i…

Fix: after 2.5.18
Fix from $1,950 2023-10-30
Admission Management System HIGH 8.8
CVE-2023-5829

A vulnerability was found in code-projects Admission Management System 1.0. It has been rated as critical. Affected by this issue is some unknown fun…

No fix yet
Fix from $1,950 2023-10-27
Sugarcrm HIGH 8.8
CVE-2023-46815

An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes…

Fix: 12.0.4+
Fix from $1,950 2023-10-27
Flusity HIGH 8.8
CVE-2023-5812

A vulnerability has been found in flusity CMS and classified as critical. Affected by this vulnerability is the function handleFileUpload of the file…

Fix: after 2.304
Fix from $1,950 2023-10-27
Pos System HIGH 8.8
CVE-2023-5796

A vulnerability was found in CodeAstro POS System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the fil…

No fix yet
Fix from $1,950 2023-10-26
Pos System HIGH 8.8
CVE-2023-5795

A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality o…

No fix yet
Fix from $1,950 2023-10-26
File Manager App CRITICAL 9.8
CVE-2023-5790

A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality o…

No fix yet
Fix from $2,300 2023-10-26
Zzzcms CRITICAL 9.8
CVE-2023-45554

File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, j…

No fix yet
Fix from $2,300 2023-10-25
Zzzcms HIGH 7.8
CVE-2023-45555

File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php…

No fix yet
Fix from $1,950 2023-10-25
Idweb HIGH 8.8
CVE-2023-26578

Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root su…

Mitigation only
Fix from $1,950 2023-10-25
Web Companion HIGH 7.3
CVE-2023-5524

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote …

Fix: 23.8 / 23.10+
Fix from $1,950 2023-10-20
Simple\ CRITICAL 9.8
CVE-2020-36706

The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/re…

Fix: 6.6.1+
Fix from $2,300 2023-10-20
Supercheckout CRITICAL 9.8
CVE-2023-45384

KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout,…

Fix: 6.0.7+
Fix from $2,300 2023-10-19
Hcl Compass HIGH 8.8
CVE-2023-37502

HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server …

Fix: 2.2.3+
Fix from $1,950 2023-10-18
Best Courier Management System HIGH 7.2
CVE-2023-46004

Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.

No fix yet
Fix from $1,950 2023-10-18
Esst Monitoring HIGH 8.8
CVE-2023-41631

eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function.

Fix: after 2.147.1
Fix from $1,950 2023-10-17
Lylme Spage CRITICAL 9.8
CVE-2023-45952

An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading …

No fix yet
Fix from $2,300 2023-10-17
Expense Management System HIGH 7.8
CVE-2023-44824

An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php componen…

No fix yet
Fix from $1,950 2023-10-17
Mailhunter Ultimate HIGH 8.8
CVE-2023-34207

Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remo…

Fix: after 2023
Fix from $1,950 2023-10-17
Security Verify Privilege On Premises HIGH 8.8
CVE-2022-22375

IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a s…

Fix: 11.5+
Fix from $1,950 2023-10-17
Reciply CRITICAL 9.8
CVE-2011-10004

A vulnerability was found in reciply Plugin up to 1.1.7 on WordPress. It has been rated as critical. This issue affects some unknown processing of th…

Fix: 1.1.8+
Fix from $2,300 2023-10-17
Security Verify Governance HIGH 7.2
CVE-2023-35018

IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.

Fix: 10.0.2+
Fix from $1,950 2023-10-16
Qdpm CRITICAL 9.8
CVE-2023-45856

qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.

No fix yet
Fix from $2,300 2023-10-14
Koha Library Software MEDIUM 5.3
CVE-2023-44962

File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl…

Fix: after 23.05.04
Fix from $1,600 2023-10-11
Smart S45f Firmware HIGH 8.8
CVE-2023-5492

A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to …

Fix: after 20230928
Fix from $1,950 2023-10-10
Smart S45f Firmware HIGH 8.8
CVE-2023-5493

A vulnerability has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as cri…

Fix: after 20230928
Fix from $1,950 2023-10-10
Smart S45f Firmware HIGH 8.8
CVE-2023-5491

A vulnerability, which was classified as critical, has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform u…

Fix: after 20230928
Fix from $1,950 2023-10-10
Smart S45f Firmware HIGH 8.8
CVE-2023-5489

A vulnerability classified as critical has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 2023092…

Fix: after 20230928
Fix from $1,950 2023-10-10