Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
I Librarian CRITICAL 9.8
CVE-2022-47854

i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.

No fix yet
Fix from $2,300 2023-01-31
Taocms CRITICAL 9.8
CVE-2022-48006

An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is expl…

No fix yet
Fix from $2,300 2023-01-30
Pandora Fms CRITICAL 9.8
CVE-2022-43979

There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha…

Fix: 766+
Fix from $2,300 2023-01-27
Magento HIGH 7.2
CVE-2021-41231

OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and…

Fix: 19.4.22 / 20.0.19+
Fix from $1,950 2023-01-27
Limesurvey CRITICAL 9.8
CVE-2022-48008

An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $2,300 2023-01-27
Bumsys HIGH 8.8
CVE-2023-0455EPSS 6%

Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.

Patch available
Fix from $1,950 2023-01-26
Learnpress CRITICAL 9.8
CVE-2022-47615EPSS 5%

Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

Fix: 4.2.0+
Fix from $2,300 2023-01-26
Mcms HIGH 8.8
CVE-2022-47042

MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.

No fix yet
Fix from $1,950 2023-01-26
Javaweb Blog CRITICAL 9.8
CVE-2022-40037

An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.

No fix yet
Fix from $2,300 2023-01-26
Blog Ssm HIGH 8.8
CVE-2022-40035

File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escalated privileges via the /uplo…

No fix yet
Fix from $1,950 2023-01-26
Act HIGH 8.8
CVE-2023-22726

act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitiz…

Fix: 0.2.40+
Fix from $1,950 2023-01-20
Dasherr CRITICAL 9.8
CVE-2023-23607

erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arb…

Fix: 1.05.00+
Fix from $2,300 2023-01-20
Xpressengine CRITICAL 9.8
CVE-2021-26642

When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insuf…

Fix: 3.0.14+
Fix from $2,300 2023-01-20
Network Services Orchestrator MEDIUM 5.5
CVE-2023-20040

A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial o…

Fix: 5.4.7 / 5.5.6+
Fix from $1,600 2023-01-20
Popojicms HIGH 8.8
CVE-2022-47766

PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.

No fix yet
Fix from $1,950 2023-01-19
Proficy Historian MEDIUM 6.5
CVE-2022-46660

An unauthorized user could alter or write files with full control over the path and content of the file.

Fix: 2023+
Fix from $1,600 2023-01-18
Tiki HIGH 7.2
CVE-2023-22851

Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.

Fix: 24.2+
Fix from $1,950 2023-01-14
Bmc HIGH 7.8
CVE-2022-42287

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances…

Fix: 00.19.07+
Fix from $1,950 2023-01-13
Online Food Ordering System CRITICAL 9.8
CVE-2023-0257

A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an u…

Mitigation only
Fix from $2,300 2023-01-12
Wukong Crm HIGH 8.8
CVE-2022-46610EPSS 18%

72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to exec…

No fix yet
Fix from $1,950 2023-01-10
B2evolution Cms HIGH 7.2
CVE-2022-44036

In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execu…

No fix yet
Fix from $1,950 2023-01-03
Easy Test HIGH 8.8
CVE-2022-43436

The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general us…

Mitigation only
Fix from $1,950 2023-01-03
Tl Wr902ac Firmware HIGH 8.8
CVE-2022-48194EPSS 33%

TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uplo…

Fix: after 3.0.9.1
Fix from $1,950 2022-12-30
Dss Express HIGH 7.2
CVE-2022-45427

Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a spe…

Patch available
Fix from $1,950 2022-12-27
Microweber HIGH 7.2
CVE-2022-4732EPSS 38%

Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.

Fix: after 1.3.1
Fix from $1,950 2022-12-27
Planet Estream CRITICAL 9.8
CVE-2022-45896

Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx ca…

Fix: 6.72.10.07+
Fix from $2,300 2022-12-25
Ampache HIGH 8.8
CVE-2022-4665

Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

Fix: 5.5.6+
Fix from $1,950 2022-12-23
Nbnbk CRITICAL 9.8
CVE-2022-46493

Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.

No fix yet
Fix from $2,300 2022-12-22
Firefox HIGH 7.8
CVE-2022-45415

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with …

Fix: 107.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-34482

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe…

Fix: 102.0+
Fix from $1,950 2022-12-22