Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Firefox HIGH 8.8
CVE-2022-34483

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe…

Fix: 102.0+
Fix from $1,950 2022-12-22
Vpn HIGH 7.8
CVE-2022-0517

Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to lau…

Fix: 2.7.1+
Fix from $1,950 2022-12-22
Ayacms CRITICAL 9.8
CVE-2022-46102

AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php

No fix yet
Fix from $2,300 2022-12-22
Classcms CRITICAL 9.8
CVE-2022-45966

here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.

No fix yet
Fix from $2,300 2022-12-22
Wbce Cms CRITICAL 9.8
CVE-2022-46020EPSS 39%

WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

No fix yet
Fix from $2,300 2022-12-20
Aerocms HIGH 7.2
CVE-2022-46135

In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and co…

No fix yet
Fix from $1,950 2022-12-16
Exact Synergy HIGH 7.8
CVE-2022-45338

An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterp…

Mitigation only
Fix from $1,950 2022-12-15
Ibarn HIGH 8.8
CVE-2020-20588

File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avata…

No fix yet
Fix from $1,950 2022-12-15
Openemr HIGH 8.8
CVE-2022-4506

Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,950 2022-12-15
Business Objects Business Intelligence Platform HIGH 8.8
CVE-2022-41267

SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objec…

Mitigation only
Fix from $1,950 2022-12-13
Dynamic Transaction Queuing System HIGH 7.2
CVE-2022-45275EPSS 15%

An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to…

No fix yet
Fix from $1,950 2022-12-12
User Registration HIGH 7.5
CVE-2022-3912

The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauth…

Fix: 2.2.4.1+
Fix from $1,950 2022-12-12
Alist HIGH 8.8
CVE-2022-45968

Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).

No fix yet
Fix from $1,950 2022-12-12
Sens HIGH 8.8
CVE-2022-45759

SENS v1.0 has a file upload vulnerability.

No fix yet
Fix from $1,950 2022-12-12
Intellij Idea HIGH 7.8
CVE-2022-46828

In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.

Fix: 2022.3+
Fix from $1,950 2022-12-08
Online Leave Management System HIGH 7.2
CVE-2022-45009

Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=up…

No fix yet
Fix from $1,950 2022-12-07
Yith Woocommerce Gift Cards CRITICAL 9.8
CVE-2022-45359EPSS 14%

Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.

Fix: after 3.19.0
Fix from $2,300 2022-12-06
Ayacms HIGH 8.8
CVE-2022-45548

AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.

No fix yet
Fix from $1,950 2022-12-06
Thinkphp HIGH 8.8
CVE-2022-44289

Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.

No fix yet
Fix from $1,950 2022-12-06
Collaboration HIGH 7.2
CVE-2022-45912

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admi…

Mitigation only
Fix from $1,950 2022-12-05
Pwndoc HIGH 8.8
CVE-2022-45771

An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted aud…

No fix yet
Fix from $1,950 2022-12-05
House Rental System CRITICAL 9.8
CVE-2022-4276

A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-…

No fix yet
Fix from $2,300 2022-12-03
Human Resource Management System CRITICAL 9.8
CVE-2022-4273

A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unk…

No fix yet
Fix from $2,300 2022-12-03
Warehouse Management System CRITICAL 9.8
CVE-2022-4272

A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /p…

No fix yet
Fix from $2,300 2022-12-03
Trufusion CRITICAL 9.8
CVE-2022-36431

An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a…

Fix: 7.9.6.1+
Fix from $2,300 2022-12-01
Event Registration System CRITICAL 9.8
CVE-2022-4232

A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The ma…

Mitigation only
Fix from $2,300 2022-11-30
Solarview Compact Firmware CRITICAL 9.8
CVE-2022-44354

SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.

No fix yet
Fix from $2,300 2022-11-29
Seo Plugin By Squirrly Seo HIGH 8.8
CVE-2022-38140

Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.

Fix: after 12.1.10
Fix from $1,950 2022-11-28
Purchase Order Management System CRITICAL 9.8
CVE-2022-44400

Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.

No fix yet
Fix from $2,300 2022-11-28
Online Tours \& Travels Management System CRITICAL 9.8
CVE-2022-44401

Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.

No fix yet
Fix from $2,300 2022-11-28