Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Webex Meetings MEDIUM 6.5
CVE-2023-20134

Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site sc…

Mitigation only
Fix from $1,600 2023-04-05
Rv340 Firmware CRITICAL 9.8
CVE-2023-20073EPSS 89%

A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthent…

Fix: after 1.0.03.29
Fix from $2,300 2023-04-05
Dynamic Transaction Queuing System HIGH 7.2
CVE-2023-26857

An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0 allows attackers to execute …

No fix yet
Fix from $1,950 2023-04-05
Community Skeleton HIGH 8.8
CVE-2023-0265

Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not pro…

No fix yet
Fix from $1,950 2023-04-04
Monitorr HIGH 7.8
CVE-2023-26775EPSS 49%

File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/up…

No fix yet
Fix from $1,950 2023-04-04
Kitecms CRITICAL 9.8
CVE-2021-31707

Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.

Mitigation only
Fix from $2,300 2023-04-04
Kitecms HIGH 7.2
CVE-2021-3267

File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.

No fix yet
Fix from $1,950 2023-04-04
Learning Management Systems CRITICAL 9.8
CVE-2023-1728

Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Inject…

Fix: 23.04.03+
Fix from $2,300 2023-04-04
Online Computer And Laptop Store CRITICAL 9.8
CVE-2023-1826

A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of …

No fix yet
Fix from $2,300 2023-04-04
Go Fastdfs CRITICAL 9.8
CVE-2023-1800

A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload o…

Fix: after 1.4.3
Fix from $2,300 2023-04-02
Otcms CRITICAL 9.8
CVE-2023-1797

A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.…

No fix yet
Fix from $2,300 2023-04-02
Cs141 Firmware CRITICAL 9.8
CVE-2022-47190

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute a…

Fix: 2.06+
Fix from $2,300 2023-03-31
Cs141 Firmware HIGH 8.8
CVE-2022-47191

Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing h…

Fix: 2.06+
Fix from $1,950 2023-03-31
Centrestack HIGH 7.2
CVE-2023-26830

An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticat…

Fix: 13.5.9808+
Fix from $1,950 2023-03-31
Ibos HIGH 8.8
CVE-2023-1744

A vulnerability classified as critical was found in IBOS 4.5.5. This vulnerability affects unknown code of the component htaccess Handler. The manipu…

Fix: after 4.5.5
Fix from $1,950 2023-03-30
Simple And Beautiful Shopping Cart System CRITICAL 9.8
CVE-2023-1739

A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown…

Mitigation only
Fix from $2,300 2023-03-30
Young Entrepreneur E Negosyo System CRITICAL 9.8
CVE-2023-1734

A vulnerability classified as critical has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected is an unknown function of t…

Mitigation only
Fix from $2,300 2023-03-30
Nextcloud Server HIGH 8.8
CVE-2023-28833

Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to …

Fix: 23.0.14 / 24.0.10+
Fix from $1,950 2023-03-30
Acymailing CRITICAL 9.8
CVE-2023-28731

AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office…

Fix: 8.3.0+
Fix from $2,300 2023-03-30
Atrocore CRITICAL 9.8
CVE-2023-26968

In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthenticated File upload.

No fix yet
Fix from $2,300 2023-03-29
Hadsky CRITICAL 9.8
CVE-2023-1684

A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the file upload/index.php?c=app&a=…

No fix yet
Fix from $2,300 2023-03-29
Mk Auth HIGH 8.8
CVE-2023-27246

An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .h…

Fix: after 23.01k4.9
Fix from $1,950 2023-03-28
Sdm600 HIGH 8.8
CVE-2022-3682

A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and upl…

Fix: 1.3.0.1339+
Fix from $1,950 2023-03-28
Ey As525f001 Firmware MEDIUM 6.5
CVE-2023-28652

An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition.

No fix yet
Fix from $1,600 2023-03-27
Pluck HIGH 7.2
CVE-2023-25828

Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collecti…

Fix: 4.7.16+
Fix from $1,950 2023-03-27
Oaklouds Portal CRITICAL 9.8
CVE-2023-25909

HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vuln…

Fix: 2.0-10 / 3.0-10+
Fix from $2,300 2023-03-27
Basercms CRITICAL 9.8
CVE-2023-25655

baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contain…

Fix: 4.7.5+
Fix from $2,300 2023-03-23
Basercms CRITICAL 9.8
CVE-2023-25654

baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of bas…

Fix: 4.7.5+
Fix from $2,300 2023-03-23
Csz Cms HIGH 8.8
CVE-2020-19786

File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file.

No fix yet
Fix from $1,950 2023-03-23
Embed Any Document MEDIUM 5.4
CVE-2023-23707

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability i…

Fix: after 2.7.1
Fix from $1,600 2023-03-23