Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Smart S45f Firmware HIGH 8.8
CVE-2023-5490

A vulnerability classified as critical was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. Th…

Fix: after 20230928
Fix from $1,950 2023-10-10
Smart S45f Firmware HIGH 8.8
CVE-2023-5488

A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. It has been rated as crit…

Fix: after 20230928
Fix from $1,950 2023-10-10
Concrete Cms MEDIUM 5.4
CVE-2023-44763

Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE:…

No fix yet
Fix from $1,600 2023-10-10
Apu0200 Firmware CRITICAL 9.8
CVE-2023-43696

Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the …

Fix: 4.0.0.6+
Fix from $2,300 2023-10-09
Unify Openscape Common Management HIGH 8.8
CVE-2023-45353

Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the…

Mitigation only
Fix from $1,950 2023-10-09
Simple And Nice Shopping Cart Script HIGH 8.8
CVE-2023-44061

File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in…

No fix yet
Fix from $1,950 2023-10-06
Pigcms CRITICAL 9.8
CVE-2023-43269

pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.

Fix: after 7.0
Fix from $2,300 2023-10-05
Dcfw 1800 Sdc Firmware HIGH 8.8
CVE-2023-43321

File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget funct…

No fix yet
Fix from $1,950 2023-10-04
Personal Management System HIGH 7.8
CVE-2023-43838

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG f…

No fix yet
Fix from $1,950 2023-10-04
Emlog CRITICAL 9.8
CVE-2023-44973

An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via upload…

No fix yet
Fix from $2,300 2023-10-03
Emlog CRITICAL 9.8
CVE-2023-44974EPSS 19%

An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2023-10-03
Et 7060 Firmware HIGH 8.8
CVE-2023-4817

This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising…

Mitigation only
Fix from $1,950 2023-10-03
Netman 204 Firmware CRITICAL 9.8
CVE-2022-47893

There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a w…

Mitigation only
Fix from $2,300 2023-10-03
Qsige HIGH 8.8
CVE-2023-4097

The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attac…

Mitigation only
Fix from $1,950 2023-10-03
Mojoportal CRITICAL 9.8
CVE-2023-44008

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

No fix yet
Fix from $2,300 2023-10-02
Mojoportal CRITICAL 9.8
CVE-2023-44009

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

No fix yet
Fix from $2,300 2023-10-02
Phpmyfaq CRITICAL 9.8
CVE-2023-5227

Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

Fix: 3.1.8+
Fix from $2,300 2023-09-30
Engineers Online Portal HIGH 8.8
CVE-2023-5284

A vulnerability classified as critical has been found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file uplo…

No fix yet
Fix from $1,950 2023-09-29
Engineers Online Portal CRITICAL 9.8
CVE-2023-5277

A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown proc…

No fix yet
Fix from $2,300 2023-09-29
Rapidcms HIGH 8.8
CVE-2023-5262

A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is the function isImg of the fi…

No fix yet
Fix from $1,950 2023-09-29
Online Book Store Project HIGH 8.8
CVE-2023-43740

Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an au…

No fix yet
Fix from $1,950 2023-09-28
Gym Management System Project HIGH 8.8
CVE-2023-5185

Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing a…

No fix yet
Fix from $1,950 2023-09-28
Dedecms HIGH 8.8
CVE-2023-43226

An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading …

Fix: after 5.7.111
Fix from $1,950 2023-09-28
Cs141 Firmware CRITICAL 9.1
CVE-2022-47186

There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, w…

Fix: 2.06+
Fix from $2,300 2023-09-28
Economizzer HIGH 8.8
CVE-2023-38874EPSS 28%

A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A…

No fix yet
Fix from $1,950 2023-09-28
Glpi CRITICAL 9.1
CVE-2023-42462

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $2,300 2023-09-27
Welcart E Commerce HIGH 7.2
CVE-2023-40219

Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.

Fix: after 2.8.21
Fix from $1,950 2023-09-27
Siberiancms HIGH 7.2
CVE-2023-39377

SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dang…

Fix: 4.20.44 / 5.0.4+
Fix from $1,950 2023-09-27
Dar 8000 Firmware HIGH 8.8
CVE-2023-5154EPSS 15%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-8000 up to 20151231 and classified as critical. This vulnerability affec…

Fix: after 2015-12-31
Fix from $1,950 2023-09-25
Dar 7000 Firmware HIGH 8.8
CVE-2023-5150EPSS 23%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an …

Fix: after 2015-12-31
Fix from $1,950 2023-09-25