Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Realgimm CRITICAL 9.8
CVE-2023-41637

An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code vi…

No fix yet
Fix from $2,300 2023-08-31
Realgimm HIGH 8.8
CVE-2023-41638

An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code…

No fix yet
Fix from $1,950 2023-08-31
Forminator CRITICAL 9.8
CVE-2023-4596EPSS 13%

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to t…

Fix: after 1.24.6
Fix from $2,300 2023-08-30
Ear CRITICAL 9.8
CVE-2020-18912

An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

No fix yet
Fix from $2,300 2023-08-29
Perfreeblog HIGH 7.2
CVE-2023-40825

An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.

No fix yet
Fix from $1,950 2023-08-28
Adm 100 Firmware CRITICAL 9.8
CVE-2023-38029

Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. …

Mitigation only
Fix from $2,300 2023-08-28
Laiketui CRITICAL 9.8
CVE-2023-4559

A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the…

Mitigation only
Fix from $2,300 2023-08-27
U Office Force CRITICAL 9.8
CVE-2023-32757

e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without …

Mitigation only
Fix from $2,300 2023-08-25
Pandora Fms HIGH 7.2
CVE-2023-24517

Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this …

Fix: after 767
Fix from $1,950 2023-08-22
Boidcms HIGH 8.8
CVE-2023-38836EPSS 74%

File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.

Mitigation only
Fix from $1,950 2023-08-21
Nbs\&happysoftwechat HIGH 8.8
CVE-2023-4409

A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality.…

No fix yet
Fix from $1,950 2023-08-18
Acymailing Starter CRITICAL 9.8
CVE-2023-39970

Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.

Fix: after 8.5.0
Fix from $2,300 2023-08-17
Online Travel Agency System HIGH 7.2
CVE-2023-31946

File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the…

No fix yet
Fix from $1,950 2023-08-17
Online Travel Agency System HIGH 7.2
CVE-2023-31941

File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the…

No fix yet
Fix from $1,950 2023-08-17
Complete Online Matrimonial Website System Script CRITICAL 9.8
CVE-2023-39115EPSS 8%

install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

No fix yet
Fix from $2,300 2023-08-16
Easyadmin8 CRITICAL 9.8
CVE-2023-38915

File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.

No fix yet
Fix from $2,300 2023-08-15
Tigergraph MEDIUM 6.5
CVE-2023-28480

An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ c…

No fix yet
Fix from $1,600 2023-08-14
Tigergraph MEDIUM 6.5
CVE-2023-28482

An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different…

No fix yet
Fix from $1,600 2023-08-14
Bloofoxcms CRITICAL 9.8
CVE-2020-36082

File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshe…

No fix yet
Fix from $2,300 2023-08-11
Avalanche CRITICAL 9.8
CVE-2023-32562EPSS 46%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve…

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Avalanche CRITICAL 9.8
CVE-2023-32564EPSS 44%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve…

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Ticket Support Script CRITICAL 9.8
CVE-2023-39776

A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.

Mitigation only
Fix from $2,300 2023-08-10
Full Customer HIGH 8.8
CVE-2023-4243

The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, …

Fix: after 2.2.3
Fix from $1,950 2023-08-09
Pharmacy Management System CRITICAL 9.8
CVE-2023-4186

A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an un…

No fix yet
Fix from $2,300 2023-08-06
Semcms HIGH 7.2
CVE-2020-23564

File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.

No fix yet
Fix from $1,950 2023-08-05
Linuxasmcallgraph CRITICAL 9.8
CVE-2023-39346

LinuxASMCallGraph is software for drawing the call graph of the programming code. Linux ASMCallGraph before commit 20dba06bd1a3cf260612d4f21547c25002…

Fix: 2022-02-08+
Fix from $2,300 2023-08-04
Omeka S HIGH 8.8
CVE-2023-4159

Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3.

Fix: 4.0.3+
Fix from $1,950 2023-08-04
Wbce Cms HIGH 7.2
CVE-2023-38947

An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a cr…

No fix yet
Fix from $1,950 2023-08-03
Dedecms HIGH 8.8
CVE-2023-36298

DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE).

No fix yet
Fix from $1,950 2023-08-03
Typecho HIGH 8.8
CVE-2023-36299

A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in in…

Patch available
Fix from $1,950 2023-08-03