Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Tiny File Manager CRITICAL 9.8
CVE-2022-45476

Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is…

No fix yet
Fix from $2,300 2022-11-25
Badaso CRITICAL 9.8
CVE-2022-41705

Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the applica…

No fix yet
Fix from $2,300 2022-11-25
Wbce Cms HIGH 7.2
CVE-2022-45039

An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP …

No fix yet
Fix from $1,950 2022-11-25
Churchinfo HIGH 8.8
CVE-2021-43258EPSS 11%

CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot h…

Fix: after 1.3.0
Fix from $1,950 2022-11-23
Op Xt71000n Firmware CRITICAL 9.8
CVE-2020-23591

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files thro…

Mitigation only
Fix from $2,300 2022-11-23
Proficy HIGH 7.8
CVE-2022-2791

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will …

Fix: after 9.00
Fix from $1,950 2022-11-22
Isic.lk HIGH 7.2
CVE-2022-30529

File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files vi…

Fix: after 2018-02-13
Fix from $1,950 2022-11-22
Api2cart Bridge Connector CRITICAL 9.8
CVE-2022-42698

Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

Mitigation only
Fix from $2,300 2022-11-18
Wpforo Forum HIGH 8.8
CVE-2022-40200

Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

Fix: after 2.0.9
Fix from $1,950 2022-11-17
Dedecms MEDIUM 6.7
CVE-2022-43192

An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code …

No fix yet
Fix from $1,600 2022-11-17
Rconfig HIGH 8.8
CVE-2022-44384EPSS 5%

An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2022-11-17
Hoosk CRITICAL 9.8
CVE-2022-43234

An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $2,300 2022-11-16
Canteen Management System CRITICAL 9.8
CVE-2022-43265

An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary …

Mitigation only
Fix from $2,300 2022-11-15
Canteen Management System HIGH 7.2
CVE-2022-43146

An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2022-11-14
Erp HIGH 8.8
CVE-2022-3944

A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the fil…

No fix yet
Fix from $1,950 2022-11-11
Remote Access Server Firmware CRITICAL 10.0
CVE-2022-40981

All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of t…

Fix: after 4.5.0
Fix from $2,300 2022-11-10
Ayacms CRITICAL 9.8
CVE-2022-43074

AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows…

No fix yet
Fix from $2,300 2022-11-10
Agentflow CRITICAL 9.8
CVE-2022-39036

The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit t…

Mitigation only
Fix from $2,300 2022-11-10
Canteen Management System HIGH 7.2
CVE-2022-43277

Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulne…

No fix yet
Fix from $1,950 2022-11-09
Roxy Fileman CRITICAL 9.8
CVE-2022-40797

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4,…

No fix yet
Fix from $2,300 2022-11-09
Online Tours And Travels Management System HIGH 7.2
CVE-2022-43050

Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. T…

No fix yet
Fix from $1,950 2022-11-07
D8s Urls CRITICAL 9.8
CVE-2022-44048

The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution b…

Mitigation only
Fix from $2,300 2022-11-07
D8s Python CRITICAL 9.8
CVE-2022-44049

The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution…

Mitigation only
Fix from $2,300 2022-11-07
D8s Networking CRITICAL 9.8
CVE-2022-44050

The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execu…

No fix yet
Fix from $2,300 2022-11-07
D8s Stats CRITICAL 9.8
CVE-2022-44051

The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution …

Mitigation only
Fix from $2,300 2022-11-07
D8s Dates CRITICAL 9.8
CVE-2022-44052

The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution …

Mitigation only
Fix from $2,300 2022-11-07
D8s Networking CRITICAL 9.8
CVE-2022-44053

The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execu…

Mitigation only
Fix from $2,300 2022-11-07
D8s Xml CRITICAL 9.8
CVE-2022-44054

The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution ba…

Mitigation only
Fix from $2,300 2022-11-07
D8s Strings CRITICAL 9.8
CVE-2022-43303

The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code executio…

Mitigation only
Fix from $2,300 2022-11-07
D8s Timer CRITICAL 9.8
CVE-2022-43304

The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution …

Mitigation only
Fix from $2,300 2022-11-07