Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Mailform CRITICAL 9.8
CVE-2023-27397

Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and serv…

Fix: 1.1.9+
Fix from $2,300 2023-05-23
Wcms CRITICAL 9.8
CVE-2023-31689EPSS 20%

In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter an…

No fix yet
Fix from $2,300 2023-05-22
Rental Module CRITICAL 9.8
CVE-2023-2712

Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows …

Fix: 23.05.15+
Fix from $2,300 2023-05-20
Perfreeblog CRITICAL 9.8
CVE-2023-30333

An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code …

No fix yet
Fix from $2,300 2023-05-18
Simple Photo Gallery CRITICAL 9.8
CVE-2023-2776

A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The m…

Mitigation only
Fix from $2,300 2023-05-17
Guppy CRITICAL 9.8
CVE-2023-31903

GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.

No fix yet
Fix from $2,300 2023-05-17
Tongda Office Anywhere CRITICAL 9.8
CVE-2023-2738

A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. …

No fix yet
Fix from $2,300 2023-05-16
Online Computer And Laptop Store CRITICAL 9.8
CVE-2023-31857

Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is …

No fix yet
Fix from $2,300 2023-05-16
Serendipity HIGH 8.8
CVE-2023-31576

An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.

No fix yet
Fix from $1,950 2023-05-16
Storage Unit Rental Management System CRITICAL 9.8
CVE-2023-30247

File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the u…

No fix yet
Fix from $2,300 2023-05-12
Extplorer HIGH 8.8
CVE-2023-29657

eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary cod…

No fix yet
Fix from $1,950 2023-05-12
Phpok HIGH 8.8
CVE-2021-34076

File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.

No fix yet
Fix from $1,950 2023-05-11
E Office CRITICAL 9.8
CVE-2023-2648EPSS 28%

A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/…

No fix yet
Fix from $2,300 2023-05-11
Tftp Server HIGH 8.8
CVE-2023-29930

An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login…

Mitigation only
Fix from $1,950 2023-05-10
Avalanche HIGH 7.2
CVE-2023-28128EPSS 85%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve…

Fix: after 6.3.4.153
Fix from $1,950 2023-05-09
Agilepoint Nx CRITICAL 9.8
CVE-2023-24507

AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.

Mitigation only
Fix from $2,300 2023-05-08
Mcms HIGH 8.8
CVE-2020-22755

File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-319…

No fix yet
Fix from $1,950 2023-05-08
Mblog HIGH 7.8
CVE-2021-27280

OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

No fix yet
Fix from $1,950 2023-05-08
Cms Made Simple HIGH 7.2
CVE-2021-28998

File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.

Fix: after 2.2.15
Fix from $1,950 2023-05-08
Crmeb CRITICAL 9.8
CVE-2023-30185

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

Fix: after 4.6.0
Fix from $2,300 2023-05-08
Semcms CRITICAL 9.8
CVE-2023-30090

Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows atta…

Mitigation only
Fix from $2,300 2023-05-05
Online Food Ordering System CRITICAL 9.8
CVE-2023-30122

An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to exec…

No fix yet
Fix from $2,300 2023-05-05
Cltphp CRITICAL 9.8
CVE-2023-30264

CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.

Fix: after 6.0
Fix from $2,300 2023-05-04
E Office CRITICAL 9.8
CVE-2023-2523EPSS 33%

A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App…

No fix yet
Fix from $2,300 2023-05-04
Jedox HIGH 8.8
CVE-2022-47878EPSS 36%

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the loca…

No fix yet
Fix from $1,950 2023-05-02
Popup HIGH 7.2
CVE-2023-0924

The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (suc…

Fix: 1.1+
Fix from $1,950 2023-05-02
Antabot White Jotter CRITICAL 9.8
CVE-2023-29635

File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function covers…

Patch available
Fix from $2,300 2023-05-01
Streampark CRITICAL 9.8
CVE-2022-45802

Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…

Fix: 2.0.0+
Fix from $2,300 2023-05-01
Dedecms HIGH 8.8
CVE-2023-2424

A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uplo…

No fix yet
Fix from $1,950 2023-04-29
Crmeb HIGH 7.2
CVE-2023-2419

A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the fil…

No fix yet
Fix from $1,950 2023-04-29