Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Bludit HIGH 8.8
CVE-2020-20210

Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

No fix yet
Fix from $1,950 2023-06-26
Cloudpanel HIGH 8.8
CVE-2023-36630

In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.

Fix: 2.3.1+
Fix from $1,950 2023-06-25
Yoga Class Registration System HIGH 7.2
CVE-2023-1721

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does n…

No fix yet
Fix from $1,950 2023-06-24
Pluck HIGH 7.2
CVE-2023-27083

An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.

Fix: 4.7.16+
Fix from $1,950 2023-06-22
Funadmin CRITICAL 9.8
CVE-2023-36097

funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.

No fix yet
Fix from $2,300 2023-06-22
Feehicms CRITICAL 9.8
CVE-2020-21174

File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.

Patch available
Fix from $2,300 2023-06-20
Wuzhicms HIGH 8.8
CVE-2020-21325

An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.

No fix yet
Fix from $1,950 2023-06-20
Nucleuscms CRITICAL 9.8
CVE-2020-21474

File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd paramet…

No fix yet
Fix from $2,300 2023-06-20
Feehicms CRITICAL 9.8
CVE-2020-21489

File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self …

Patch available
Fix from $2,300 2023-06-20
Ebcms HIGH 8.8
CVE-2020-20067

File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.

No fix yet
Fix from $1,950 2023-06-20
Pluckcms CRITICAL 9.8
CVE-2020-20718

File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the sa…

Patch available
Fix from $2,300 2023-06-20
Ljcms CRITICAL 9.8
CVE-2020-20735

File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.

Mitigation only
Fix from $2,300 2023-06-20
Pluck HIGH 7.2
CVE-2020-20919

File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the them…

No fix yet
Fix from $1,950 2023-06-20
Pluck HIGH 7.2
CVE-2020-20969EPSS 6%

File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.

Patch available
Fix from $1,950 2023-06-20
Sugarcrm HIGH 8.8
CVE-2023-35808

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in…

Fix: 11.0.6 / 12.0.3+
Fix from $1,950 2023-06-17
Unlimited Elements For Elementor HIGH 8.8
CVE-2023-3295

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type…

Fix: 1.5.67+
Fix from $1,950 2023-06-17
Jeecg Boot MEDIUM 6.5
CVE-2023-34660

jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.

No fix yet
Fix from $1,600 2023-06-16
Bludit MEDIUM 5.4
CVE-2023-34845

Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attack…

No fix yet
Fix from $1,600 2023-06-16
Instantqos CRITICAL 9.8
CVE-2023-32752

L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticat…

Mitigation only
Fix from $2,300 2023-06-16
Omicard Edm CRITICAL 9.8
CVE-2023-32753

OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulne…

Mitigation only
Fix from $2,300 2023-06-16
Thinkadmin MEDIUM 6.1
CVE-2023-34833

An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crafted fil…

No fix yet
Fix from $1,600 2023-06-15
Supplier Management System HIGH 8.8
CVE-2023-3274

A vulnerability classified as critical has been found in code-projects Supplier Management System 1.0. Affected is an unknown function of the file bt…

No fix yet
Fix from $1,950 2023-06-15
Security Directory Suite Va HIGH 7.2
CVE-2022-33166

IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automat…

Fix: after 8.0.1.19
Fix from $1,950 2023-06-15
Ujcms CRITICAL 9.8
CVE-2023-34747EPSS 20%

File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.

No fix yet
Fix from $2,300 2023-06-14
Chamilo Lms CRITICAL 9.8
CVE-2023-34944

An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary co…

Fix: after 1.11.18
Fix from $2,300 2023-06-13
Ckeditor CRITICAL 9.8
CVE-2023-31541

A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which al…

Mitigation only
Fix from $2,300 2023-06-13
Lockcell Firmware CRITICAL 9.8
CVE-2023-3049

Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15.

Fix: 15.0+
Fix from $2,300 2023-06-13
Labcollector HIGH 8.8
CVE-2023-33253

LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute …

Fix: after 6.15
Fix from $1,950 2023-06-12
Teachers Record Management System MEDIUM 5.4
CVE-2023-3187

A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some…

No fix yet
Fix from $1,600 2023-06-09
Vuforia Studio CRITICAL 9.9
CVE-2023-27881

A user could use the “Upload Resource” functionality to upload files to any location on the disk.

Fix: 9.9+
Fix from $2,300 2023-06-07