Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Storage Unit Rental Management System HIGH 7.2
CVE-2023-1559

A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vulnerability affects unknown c…

No fix yet
Fix from $1,950 2023-03-22
Simple Online Hotel Reservation System CRITICAL 9.8
CVE-2023-1561

A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown func…

Mitigation only
Fix from $2,300 2023-03-22
Simple And Beautiful Shopping Cart System CRITICAL 9.8
CVE-2023-1558

A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uplo…

Mitigation only
Fix from $2,300 2023-03-22
Crypto Application Server CRITICAL 9.1
CVE-2023-28725EPSS 21%

General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary …

No fix yet
Fix from $2,300 2023-03-22
Rockoa HIGH 8.8
CVE-2023-1501

A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL…

No fix yet
Fix from $1,950 2023-03-19
Simple And Nice Shopping Cart Script CRITICAL 9.8
CVE-2023-1497

A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown …

Mitigation only
Fix from $2,300 2023-03-19
Xzjie Cms CRITICAL 9.8
CVE-2023-1484

A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. This issue affects some unknown processing of the file /api/upload. Th…

Fix: after 1.0.3
Fix from $2,300 2023-03-18
Simple Music Player CRITICAL 9.8
CVE-2023-1479

A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. Affected is an unknown function of the file save_mus…

No fix yet
Fix from $2,300 2023-03-18
Qykcms HIGH 7.2
CVE-2023-1442

A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. It has been classified as problematic. This affects an unknown part of the file /admin_s…

No fix yet
Fix from $1,950 2023-03-17
Gadget Works Online Ordering System HIGH 7.2
CVE-2023-1433

A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problematic. This affects an unknown p…

No fix yet
Fix from $1,950 2023-03-16
Rax30 Firmware HIGH 8.8
CVE-2023-28337

When uploading a firmware image to a Netgear Nighthawk Wifi6 Router (RAX30), a hidden “forceFWUpdate” parameter may be provided to force the upgrade …

Mitigation only
Fix from $1,950 2023-03-15
Simple Art Gallery HIGH 8.8
CVE-2023-1415

A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the function sliderPicSubmit of the…

No fix yet
Fix from $1,950 2023-03-15
Jizhicms HIGH 7.2
CVE-2023-27235

An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code v…

No fix yet
Fix from $1,950 2023-03-15
Perfreeblog CRITICAL 9.8
CVE-2023-27757

An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a …

No fix yet
Fix from $2,300 2023-03-15
Experience Manager HIGH 7.2
CVE-2023-26262

An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can l…

Fix: 10.3+
Fix from $1,950 2023-03-14
Online Tours \& Travels Management System CRITICAL 9.8
CVE-2023-1391

A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknow…

Mitigation only
Fix from $2,300 2023-03-14
Online Pizza Ordering System CRITICAL 9.8
CVE-2023-1392

A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is the f…

No fix yet
Fix from $2,300 2023-03-14
Auto Featured Image HIGH 8.8
CVE-2023-0477

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author priv…

Fix: 3.9.16+
Fix from $1,950 2023-03-13
Avantfax HIGH 8.8
CVE-2023-23328

A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a spec…

Mitigation only
Fix from $1,950 2023-03-10
115cms HIGH 7.2
CVE-2023-1328

A vulnerability was found in Guizhou 115cms 4.2. It has been classified as problematic. Affected is an unknown function of the file /admin/content/in…

No fix yet
Fix from $1,950 2023-03-10
Cockpit HIGH 8.8
CVE-2023-1313

Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.

Fix: after 2.4.0
Fix from $1,950 2023-03-10
Ucms CRITICAL 9.8
CVE-2023-1303

A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the c…

Mitigation only
Fix from $2,300 2023-03-09
Help Desk CRITICAL 9.8
CVE-2021-33352

An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file uploa…

Fix: 1.3.7+
Fix from $2,300 2023-03-08
Zephyr Enterprise HIGH 7.5
CVE-2023-22890

SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a d…

Fix: after 7.15
Fix from $1,950 2023-03-08
Designfolio Plus HIGH 8.8
CVE-2015-10087

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in UpThemes Theme DesignFolio Plus 1.2 on WordPress and classified as problematic. Aff…

Fix: after 1.2
Fix from $1,950 2023-03-07
Envato Elements HIGH 8.8
CVE-2021-4330

The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validatio…

Fix: after 2.0.10
Fix from $1,950 2023-03-07
Onekeyadmin CRITICAL 9.8
CVE-2023-26949

An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a …

No fix yet
Fix from $2,300 2023-03-06
Ecshop HIGH 8.8
CVE-2023-1184

A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of t…

Fix: after 4.1.8
Fix from $1,950 2023-03-06
Ecshop HIGH 8.8
CVE-2023-1185

A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Hand…

Fix: after 4.1.8
Fix from $1,950 2023-03-06
Yf Exam HIGH 7.5
CVE-2023-25402

CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload.

No fix yet
Fix from $1,950 2023-03-03