Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Smart S85f CRITICAL 9.8
CVE-2023-4121

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. Affected is an unknown functio…

Fix: after 20230722
Fix from $2,300 2023-08-03
Total Cms HIGH 8.8
CVE-2023-36212EPSS 26%

File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function.

No fix yet
Fix from $1,950 2023-08-03
Eshop MEDIUM 5.3
CVE-2023-38330

OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upl…

Fix: 6.5.3+
Fix from $1,600 2023-08-02
Brocade Fabric Operating System MEDIUM 5.5
CVE-2023-31428

Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow a local user to dump files u…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
Uvdesk HIGH 7.8
CVE-2023-39147

An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.

No fix yet
Fix from $1,950 2023-08-01
Ajaxmanager CRITICAL 9.8
CVE-2023-33493

An Unrestricted Upload of File with Dangerous Type vulnerability in the Ajaxmanager File and Database explorer (ajaxmanager) module for PrestaShop th…

Fix: after 2.3.0
Fix from $2,300 2023-08-01
Sysaid On Premises HIGH 7.2
CVE-2023-32225

Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangero…

Fix: 23.2.14+
Fix from $1,950 2023-07-30
E Office CRITICAL 9.8
CVE-2023-34798

An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

Fix: 9.5+
Fix from $2,300 2023-07-25
Pligg Cms CRITICAL 9.8
CVE-2023-37677

Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.

No fix yet
Fix from $2,300 2023-07-25
Report Server HIGH 7.5
CVE-2022-46899

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Arbitrary File Upload. The BaseController class, that each…

Fix: after 5.8.0.135
Fix from $1,950 2023-07-25
Papercut Mf HIGH 7.5
CVE-2023-3486EPSS 79%

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary fil…

Fix: 22.1.3+
Fix from $1,950 2023-07-25
Gbrowse CRITICAL 9.8
CVE-2023-32637

GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who ca…

Mitigation only
Fix from $2,300 2023-07-25
Netact HIGH 8.8
CVE-2022-28863

An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitraril…

No fix yet
Fix from $1,950 2023-07-24
Rapidcms HIGH 7.2
CVE-2023-3852EPSS 25%

A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been declared as critical. This vulnerability affects unknown code of the file /a…

Fix: after 1.3.1
Fix from $1,950 2023-07-23
Smart Parking Management CRITICAL 9.8
CVE-2023-3836EPSS 74%

A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /…

Fix: after 20230713
Fix from $2,300 2023-07-22
House Rental And Property Listing Php CRITICAL 9.8
CVE-2023-3806

A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown f…

No fix yet
Fix from $2,300 2023-07-21
Flash Flood Disaster Monitoring And Warning System CRITICAL 9.8
CVE-2023-3804

A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unk…

No fix yet
Fix from $2,300 2023-07-21
Flash Flood Disaster Monitoring And Warning System CRITICAL 9.8
CVE-2023-3802

A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue…

No fix yet
Fix from $2,300 2023-07-21
Easyadmin8 MEDIUM 6.6
CVE-2023-3800

A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function of the file /admin/index/inde…

Mitigation only
Fix from $1,600 2023-07-20
Four Mountain Torrent Disaster Prevention\, Control Monitoring And Early Warning System HIGH 8.8
CVE-2023-3797

A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring an…

No fix yet
Fix from $1,950 2023-07-20
Flash Flood Disaster Monitoring And Warning System CRITICAL 9.8
CVE-2023-3798

A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affec…

No fix yet
Fix from $2,300 2023-07-20
Foody Friend HIGH 8.8
CVE-2023-3796

A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0. Affected by this issue is some unknown functiona…

Mitigation only
Fix from $1,950 2023-07-20
Document On Line Submission And Approval System CRITICAL 9.8
CVE-2023-37289

It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submi…

Mitigation only
Fix from $2,300 2023-07-20
Geolocation Server HIGH 7.8
CVE-2023-34394

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYS…

Fix: after 2.4.2
Fix from $1,950 2023-07-19
Aura Device Services CRITICAL 9.8
CVE-2023-3722

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web …

Fix: after 8.1.4.0
Fix from $2,300 2023-07-19
Pygments MEDIUM 5.5
CVE-2022-40896

A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

Fix: after 2.15.0
Fix from $1,600 2023-07-19
Scrutisweb CRITICAL 9.8
CVE-2023-35189

Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote code execution vulnerability that could allow an unauthenticated user to upl…

Fix: after 2.1.37
Fix from $2,300 2023-07-18
3080ipx Firmware HIGH 8.8
CVE-2020-22159

EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticate…

No fix yet
Fix from $1,950 2023-07-18
Infoscale Operations Manager HIGH 8.8
CVE-2023-38404

The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of fi…

Fix: 8.0.0.410+
Fix from $1,950 2023-07-17
Admidio HIGH 7.2
CVE-2023-3692

Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10.

Fix: 4.2.10+
Fix from $1,950 2023-07-16