Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Textpattern HIGH 8.8
CVE-2023-24269

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Z…

No fix yet
Fix from $1,950 2023-04-28
Spotfire Statistics Services CRITICAL 9.8
CVE-2023-29268

The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote…

Fix: 11.4.11+
Fix from $2,300 2023-04-26
Drupal HIGH 7.2
CVE-2022-25277

Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenam…

Fix: 9.3.19 / 9.4.3+
Fix from $1,950 2023-04-26
Cltphp HIGH 8.8
CVE-2023-30266

CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.

Fix: after 6.0
Fix from $1,950 2023-04-26
Cloud Pak For Data HIGH 7.2
CVE-2022-36769

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…

Mitigation only
Fix from $1,950 2023-04-26
Apsal HIGH 7.8
CVE-2023-26098

An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted file to execute arbitrary co…

Mitigation only
Fix from $1,950 2023-04-25
Kiwi Tcms CRITICAL 9.0
CVE-2023-30613

Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior t…

Fix: 12.2+
Fix from $2,300 2023-04-24
Lantime Firmware HIGH 7.2
CVE-2023-1731

In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an re…

Fix: 7.06.013+
Fix from $1,950 2023-04-24
Powerpanel CRITICAL 9.8
CVE-2023-25132

Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier,…

Fix: after 4.8.6
Fix from $2,300 2023-04-24
Online Pizza Ordering System CRITICAL 9.8
CVE-2023-2246

A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code…

No fix yet
Fix from $2,300 2023-04-23
Hansuncms MEDIUM 6.3
CVE-2023-2245

A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/cont…

No fix yet
Fix from $1,600 2023-04-22
Junos CRITICAL 9.8
CVE-2023-28962

An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, netw…

Fix: 19.4+
Fix from $2,300 2023-04-17
Go Bbs HIGH 8.8
CVE-2023-27755

go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download.

No fix yet
Fix from $1,950 2023-04-17
Positions CRITICAL 9.8
CVE-2022-34128EPSS 8%

The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

Fix: 6.0.1+
Fix from $2,300 2023-04-16
Employee Performance Evaluation System HIGH 8.8
CVE-2023-29625

Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitr…

No fix yet
Fix from $1,950 2023-04-14
Online Pizza Ordering HIGH 8.8
CVE-2023-29627

Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a cr…

No fix yet
Fix from $1,950 2023-04-14
Purchase Order Management HIGH 8.8
CVE-2023-29621

Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via …

No fix yet
Fix from $1,950 2023-04-14
Froxlor HIGH 8.8
CVE-2023-2034EPSS 73%

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

Fix: 2.0.14+
Fix from $1,950 2023-04-14
Textpattern HIGH 7.2
CVE-2023-26852

An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a…

Fix: after 4.8.8
Fix from $1,950 2023-04-12
Doyocms CRITICAL 9.8
CVE-2020-19802

File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.

Mitigation only
Fix from $2,300 2023-04-11
Gdidees Cms HIGH 7.5
CVE-2023-27179EPSS 61%

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

Fix: after 3.9.1
Fix from $1,950 2023-04-11
Gdidees Cms CRITICAL 9.8
CVE-2023-27178

An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.

Mitigation only
Fix from $2,300 2023-04-10
Tpadmin HIGH 7.2
CVE-2023-1970

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin 1.3.12. This issue affects t…

No fix yet
Fix from $1,950 2023-04-10
Sitefinity CRITICAL 9.8
CVE-2023-29375

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 b…

Fix: 13.3.7646 / 14.0.7736+
Fix from $2,300 2023-04-10
Jetengine For Elementor HIGH 8.8
CVE-2023-1406

The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote c…

Fix: 3.1.3.1+
Fix from $1,950 2023-04-10
Linkis CRITICAL 9.8
CVE-2023-27602

In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme…

Fix: after 1.3.1
Fix from $2,300 2023-04-10
Cdesigner CRITICAL 9.8
CVE-2023-27033

Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontContro…

Fix: 3.2.2+
Fix from $2,300 2023-04-07
Online Computer And Laptop Store CRITICAL 9.8
CVE-2023-1942

A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is a…

No fix yet
Fix from $2,300 2023-04-07
Readium Js CRITICAL 9.8
CVE-2023-24720

An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.

No fix yet
Fix from $2,300 2023-04-05
Ulearn HIGH 7.2
CVE-2023-0670

Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the serv…

Mitigation only
Fix from $1,950 2023-04-05