Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Dar 7000 Firmware HIGH 8.8
CVE-2023-5147EPSS 27%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been classified as critical. This affects an unkn…

Fix: after 2015-12-31
Fix from $1,950 2023-09-25
Dar 7000 Firmware HIGH 8.8
CVE-2023-5148EPSS 31%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vuln…

Fix: after 2015-12-31
Fix from $1,950 2023-09-25
Dar 7000 Firmware HIGH 8.8
CVE-2023-5149EPSS 21%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. This issue affects some u…

Fix: after 2015-12-31
Fix from $1,950 2023-09-25
Dar 7000 Firmware HIGH 8.8
CVE-2023-5146EPSS 33%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231 and classified as critical. Affected by this…

Fix: after 20151231
Fix from $1,950 2023-09-25
Dar 7000 Firmware HIGH 8.8
CVE-2023-5145EPSS 34%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000 up to 20151231 and classified as critical. Affected by this vulnera…

Fix: after 20151231
Fix from $1,950 2023-09-25
Dar 7000 Firmware HIGH 8.8
CVE-2023-5144EPSS 6%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected…

Fix: after 20151231
Fix from $1,950 2023-09-24
Dataease MEDIUM 5.3
CVE-2023-40183

DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to…

Fix: 1.18.11+
Fix from $1,600 2023-09-21
Elite Cms HIGH 8.8
CVE-2023-42331

A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.

No fix yet
Fix from $1,950 2023-09-20
Crew HIGH 8.8
CVE-2023-42335

Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the ad…

No fix yet
Fix from $1,950 2023-09-20
Jenkins HIGH 8.1
CVE-2023-43497

In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default…

Fix: 2.414.2 / 2.424+
Fix from $1,950 2023-09-20
Arcadyan Lh1000 Firmware CRITICAL 9.8
CVE-2023-43478EPSS 17%

fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware…

Fix: 0.18.15r+
Fix from $2,300 2023-09-20
Macupdater HIGH 7.8
CVE-2023-41902

An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting …

Fix: 2.3.8 / 3.1.2+
Fix from $1,950 2023-09-20
Croc HIGH 7.8
CVE-2023-43619

An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized_k…

Fix: after 9.6.5
Fix from $1,950 2023-09-20
Dolibarr Erp\/crm HIGH 8.8
CVE-2023-38887

File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information…

Fix: after 17.0.1
Fix from $1,950 2023-09-20
Openupload HIGH 8.8
CVE-2023-36319

File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-in…

No fix yet
Fix from $1,950 2023-09-20
My Food Recipe CRITICAL 9.8
CVE-2023-5034

A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.p…

Mitigation only
Fix from $2,300 2023-09-18
Laiketui CRITICAL 9.8
CVE-2023-4988

A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of the file index.php?module=sys…

Mitigation only
Fix from $2,300 2023-09-15
Lenosp HIGH 8.8
CVE-2023-42180

An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file.

Fix: after 1.2.0
Fix from $1,950 2023-09-14
Gotham Cerberus MEDIUM 5.4
CVE-2023-30962

The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Go…

Fix: 100.230704.0-27-g031dd58+
Fix from $1,600 2023-09-12
Dedecms CRITICAL 9.8
CVE-2023-40784

DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

Mitigation only
Fix from $2,300 2023-09-12
Factorytalk View CRITICAL 9.8
CVE-2023-2071EPSS 11%

Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t…

Fix: after 13.0
Fix from $2,300 2023-09-12
Qms Automotive HIGH 8.8
CVE-2023-40731

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. …

Fix: 12.39+
Fix from $1,950 2023-09-12
Businessobjects Business Intelligence Platform HIGH 7.3
CVE-2023-42472

Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows …

Mitigation only
Fix from $1,950 2023-09-12
Cockpit MEDIUM 6.1
CVE-2023-41564

An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a …

Mitigation only
Fix from $1,600 2023-09-08
Internet Reservation Module Next Generation HIGH 8.8
CVE-2023-39424

A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such…

Mitigation only
Fix from $1,950 2023-09-07
Bolo Solo CRITICAL 9.8
CVE-2023-41009

File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization fie…

Mitigation only
Fix from $2,300 2023-09-05
Bookreen HIGH 7.2
CVE-2023-3375

Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3…

Fix: 3.0.0+
Fix from $1,950 2023-09-05
Tef Portal HIGH 8.8
CVE-2023-41108

TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.

No fix yet
Fix from $1,950 2023-09-05
Smart S85f Firmware CRITICAL 9.8
CVE-2023-4739

A vulnerability, which was classified as critical, has been found in Byzoro Smart S85F Management Platform up to 20230820. Affected by this issue is …

Fix: after 20230820
Fix from $2,300 2023-09-03
Dwsurvey CRITICAL 9.8
CVE-2023-40980

File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and…

Fix: after 3.2.0
Fix from $2,300 2023-09-01