Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Email Security Appliance HIGH 7.2
CVE-2023-20009

A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow…

Fix: 12.5.3-041 / 12.8.1-021+
Fix from $1,950 2023-03-01
Data Science Studio MEDIUM 6.5
CVE-2023-24045

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a …

Fix: 11.3.2+
Fix from $1,600 2023-03-01
Laravel Admin HIGH 7.2
CVE-2023-24249

An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2023-02-27
Erp HIGH 8.8
CVE-2023-26762

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability.

No fix yet
Fix from $1,950 2023-02-27
Balero Cms HIGH 7.2
CVE-2021-35290

File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /admin/main/mod-blog page.

Mitigation only
Fix from $1,950 2023-02-24
Umbraco Forms CRITICAL 9.8
CVE-2021-33224

File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

Mitigation only
Fix from $2,300 2023-02-24
Judging Management System HIGH 8.1
CVE-2023-24317

Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

Mitigation only
Fix from $1,950 2023-02-23
Rd3 CRITICAL 9.8
CVE-2022-39983

File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2023-02-22
Cloudflow CRITICAL 9.8
CVE-2022-41217

Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PR…

Fix: 2.3.2+
Fix from $2,300 2023-02-22
Octopus Server HIGH 7.5
CVE-2022-2883

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

Fix: 2022.3.11043 / 2022.4.8401+
Fix from $1,950 2023-02-22
Best Pos Management System HIGH 8.8
CVE-2023-0943

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the functio…

Mitigation only
Fix from $1,950 2023-02-21
Pharmacy Management System CRITICAL 9.8
CVE-2023-0918

A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of …

Mitigation only
Fix from $2,300 2023-02-19
Bearadmin CRITICAL 9.8
CVE-2021-35261

File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote co…

No fix yet
Fix from $2,300 2023-02-17
Businessobjects Business Intelligence Platform CRITICAL 9.1
CVE-2023-24530

SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be…

Mitigation only
Fix from $2,300 2023-02-14
Business Planning And Consolidation MEDIUM 5.4
CVE-2023-23851

SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages)…

Mitigation only
Fix from $1,600 2023-02-14
Online Food Ordering System CRITICAL 9.8
CVE-2023-24646

An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code v…

No fix yet
Fix from $2,300 2023-02-13
Enable Media Replace HIGH 8.8
CVE-2023-0255

The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to u…

Fix: 4.0.2+
Fix from $1,950 2023-02-13
Ecshop CRITICAL 9.8
CVE-2023-0783

A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of…

No fix yet
Fix from $2,300 2023-02-11
Institutional Management Website CRITICAL 9.8
CVE-2022-45527

File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious file…

No fix yet
Fix from $2,300 2023-02-08
Raffle Draw System CRITICAL 9.8
CVE-2023-24202

Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

No fix yet
Fix from $2,300 2023-02-06
Pimcore MEDIUM 5.4
CVE-2023-23937

Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updatin…

Fix: 10.5.16+
Fix from $1,600 2023-02-03
Phpwcms HIGH 8.8
CVE-2021-36426

File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php.

Fix: 1.9.26+
Fix from $1,950 2023-02-03
Aapanel Host System CRITICAL 9.8
CVE-2022-48079

Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploadi…

No fix yet
Fix from $2,300 2023-02-02
Fastcms CRITICAL 9.8
CVE-2023-0651

A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management.…

Mitigation only
Fix from $2,300 2023-02-02
Responsive Filemanager HIGH 8.8
CVE-2022-46604EPSS 9%

An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP fi…

Fix: after 9.9.5
Fix from $1,950 2023-02-02
Ftdms HIGH 7.2
CVE-2023-23135

An arbitrary file upload vulnerability in Ftdms v3.1.6 allows attackers to execute arbitrary code via uploading a crafted JPG file.

No fix yet
Fix from $1,950 2023-02-01
Nosh Chartingsystem HIGH 8.8
CVE-2023-24610

NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be by…

Mitigation only
Fix from $1,950 2023-02-01
Apc Easy Ups Online Monitoring Software CRITICAL 9.8
CVE-2022-42971

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a ma…

Fix: 2.5-ga / 2.5-gs+
Fix from $2,300 2023-02-01
Apex One CRITICAL 9.1
CVE-2023-0587EPSS 60%

A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent…

Mitigation only
Fix from $2,300 2023-02-01
Fast Checkin CRITICAL 9.8
CVE-2022-47769

An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the …

Mitigation only
Fix from $2,300 2023-02-01