Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Dedecms CRITICAL 9.8
CVE-2023-37839

An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading …

No fix yet
Fix from $2,300 2023-07-13
User Registration CRITICAL 9.9
CVE-2023-3342

The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation…

Fix: 3.0.2.1+
Fix from $2,300 2023-07-13
Analytics CRITICAL 9.8
CVE-2023-34136

Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…

Fix: 9.3.2+
Fix from $2,300 2023-07-13
Analytics HIGH 8.8
CVE-2023-34126

Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This…

Fix: 9.3.2+
Fix from $1,950 2023-07-13
Simple Online Piggery Management System CRITICAL 9.8
CVE-2023-37629EPSS 23%

Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pi…

No fix yet
Fix from $2,300 2023-07-12
Mountain Flood Disaster Prevention Monitoring And Early Warning System CRITICAL 9.8
CVE-2023-3625

A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. …

Fix: after 2023-07-06
Fix from $2,300 2023-07-11
Mountain Flood Disaster Prevention Monitoring And Early Warning System CRITICAL 9.8
CVE-2023-3626

A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System…

Fix: after 20230706
Fix from $2,300 2023-07-11
Mountain Flood Disaster Prevention Monitoring And Early Warning System CRITICAL 9.8
CVE-2023-3623

A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as cr…

Fix: after 2023-07-04
Fix from $2,300 2023-07-11
Websiteguide CRITICAL 9.8
CVE-2023-37656

WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.

No fix yet
Fix from $2,300 2023-07-11
Online Art Gallery CRITICAL 9.8
CVE-2023-37152

Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This ha…

No fix yet
Fix from $2,300 2023-07-10
Collaboration HIGH 8.8
CVE-2023-34193

File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via…

Mitigation only
Fix from $1,950 2023-07-06
Cms Made Simple HIGH 8.8
CVE-2023-36969EPSS 49%

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

No fix yet
Fix from $1,950 2023-07-06
Duxcms HIGH 8.8
CVE-2020-21861

File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.

No fix yet
Fix from $1,950 2023-07-06
Kiwi Tcms MEDIUM 5.4
CVE-2023-36809

Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12…

Fix: 12.5+
Fix from $1,600 2023-07-05
Firefox HIGH 7.8
CVE-2023-37208

When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Fire…

Fix: 102.13 / 115.0+
Fix from $1,950 2023-07-05
Shopping Website HIGH 8.8
CVE-2023-3503

A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $1,950 2023-07-04
Smartweb Infotech Job Board CRITICAL 9.8
CVE-2023-3504

A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Mitigation only
Fix from $2,300 2023-07-04
Fuel Cms CRITICAL 9.8
CVE-2020-22151

Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of t…

No fix yet
Fix from $2,300 2023-07-03
Fuel Cms CRITICAL 9.8
CVE-2020-22153

File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in t…

No fix yet
Fix from $2,300 2023-07-03
Fossbilling HIGH 8.8
CVE-2023-3491

Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

Fix: 0.5.3+
Fix from $1,950 2023-06-30
Wl Wn531ax2 Firmware HIGH 7.2
CVE-2023-32621

WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands …

Fix: 2023526+
Fix from $1,950 2023-06-30
Semcms CRITICAL 9.8
CVE-2020-18432

File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.

Mitigation only
Fix from $2,300 2023-06-30
Chemex CRITICAL 9.8
CVE-2023-34738

Chemex through 3.7.1 is vulnerable to arbitrary file upload.

Fix: after 3.7.1
Fix from $2,300 2023-06-29
Guantang Equipment Management System HIGH 7.2
CVE-2023-34736

Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.

No fix yet
Fix from $1,950 2023-06-28
Responsive Filemanager CRITICAL 9.8
CVE-2022-44276

In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

Fix: 9.12.0+
Fix from $2,300 2023-06-28
Mobile Security MEDIUM 6.5
CVE-2023-32525

Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affe…

Patch available
Fix from $1,600 2023-06-26
Mobile Security MEDIUM 6.5
CVE-2023-32526

Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affe…

Patch available
Fix from $1,600 2023-06-26
Blogengine.net CRITICAL 9.8
CVE-2023-33404EPSS 26%

An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allow…

Fix: after 3.3.8.0
Fix from $2,300 2023-06-26
Bludit HIGH 8.8
CVE-2020-20210

Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

No fix yet
Fix from $1,950 2023-06-26
Cloudpanel HIGH 8.8
CVE-2023-36630

In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.

Fix: 2.3.1+
Fix from $1,950 2023-06-25