Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Alist HIGH 8.8
CVE-2023-33498

alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.

Fix: 3.16.3+
Fix from $1,950 2023-06-07
Adning Advertising CRITICAL 9.8
CVE-2020-36705EPSS 7%

The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image fun…

Fix: 1.5.6+
Fix from $2,300 2023-06-07
Recently HIGH 8.8
CVE-2021-4382

The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function …

Fix: 3.0.5+
Fix from $1,950 2023-06-07
Adsanity HIGH 8.8
CVE-2022-4949

The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versio…

Fix: 1.8.2+
Fix from $1,950 2023-06-07
Phpok HIGH 8.8
CVE-2023-33601

An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2023-06-07
Pwa For Wp \& Amp HIGH 8.8
CVE-2021-4354

The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader …

Fix: 1.7.33+
Fix from $1,950 2023-06-07
Page Builder King Composer HIGH 8.8
CVE-2020-36701

The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_…

Fix: after 2.9.3
Fix from $1,950 2023-06-07
Delete All Comments CRITICAL 9.8
CVE-2016-15033

The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-co…

Fix: after 2.0
Fix from $2,300 2023-06-07
User Submitted Posts CRITICAL 9.8
CVE-2019-25138

The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images fun…

Fix: after 20190312
Fix from $2,300 2023-06-07
Faculty Evaluation System HIGH 7.2
CVE-2023-33569

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.

No fix yet
Fix from $1,950 2023-06-06
Webaccess\/scada CRITICAL 9.8
CVE-2023-32628

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extensi…

Fix: after 9.1.3
Fix from $2,300 2023-06-06
Webaccess\/scada HIGH 7.2
CVE-2023-22450

In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script fi…

Fix: after 9.1.3
Fix from $1,950 2023-06-06
Emlog HIGH 7.5
CVE-2020-19028

*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php…

No fix yet
Fix from $1,950 2023-06-05
Jms Slider CRITICAL 9.8
CVE-2023-29631

PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.

Mitigation only
Fix from $2,300 2023-06-05
Marsctf CRITICAL 9.8
CVE-2023-33386

MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.

No fix yet
Fix from $2,300 2023-06-05
Agro School Management System CRITICAL 9.8
CVE-2023-3061

A vulnerability was found in code-projects Agro-School Management System 1.0 and classified as critical. This issue affects some unknown processing o…

No fix yet
Fix from $2,300 2023-06-02
Mobatime Web Application HIGH 8.8
CVE-2023-3032

Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user …

Fix: after 06.7.22
Fix from $1,950 2023-06-02
Fantasy HIGH 8.8
CVE-2023-28699

Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An authenticated remote attacker …

Mitigation only
Fix from $1,950 2023-06-02
Omicard Edm MEDIUM 6.8
CVE-2023-28700

OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with adminis…

Mitigation only
Fix from $1,600 2023-06-02
Fx5 Enet\/ip Firmware HIGH 7.3
CVE-2023-2063

Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP modul…

Mitigation only
Fix from $1,950 2023-06-02
Vaultpress CRITICAL 9.8
CVE-2014-125104

A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the func…

Fix: 1.6.1+
Fix from $2,300 2023-06-01
Via Go2 Firmware CRITICAL 9.8
CVE-2023-33508

KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).

Fix: 4.0.1.1326+
Fix from $2,300 2023-05-31
Insight HIGH 8.8
CVE-2023-28353

An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on …

No fix yet
Fix from $1,950 2023-05-31
Parse Server MEDIUM 6.5
CVE-2023-32689

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 5.4.4 and 6.1.1 are vulnera…

Fix: 5.4.4 / 6.1.1+
Fix from $1,600 2023-05-30
Simfield Firmware CRITICAL 9.8
CVE-2023-2924EPSS 24%

A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this issue is some unknown functio…

Fix: after 1.80.00.00
Fix from $2,300 2023-05-27
Kiwi Tcms MEDIUM 5.4
CVE-2023-32686

Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans,…

Fix: after 12.2
Fix from $1,600 2023-05-27
Confluence Server MEDIUM 6.5
CVE-2023-22504

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload att…

Fix: 7.13.17 / 7.19.9+
Fix from $1,600 2023-05-25
Phpok HIGH 8.8
CVE-2023-2888

A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&…

No fix yet
Fix from $1,950 2023-05-25
Sofawiki CRITICAL 9.8
CVE-2023-29721

SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.

Fix: after 3.8.9
Fix from $2,300 2023-05-24
Mw Wp Form CRITICAL 9.8
CVE-2023-28409

Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker t…

Fix: after 4.4.2
Fix from $2,300 2023-05-23