Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
D8s Python CRITICAL 9.8
CVE-2022-43305

The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution…

Mitigation only
Fix from $2,300 2022-11-07
D8s Timer HIGH 8.8
CVE-2022-43306

The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution …

Mitigation only
Fix from $1,950 2022-11-07
Role Based Pricing For Woocommerce HIGH 8.8
CVE-2022-3537

The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files …

Fix: 1.6.2+
Fix from $1,950 2022-11-07
Online Tours \& Travels Management System HIGH 7.2
CVE-2022-43061

Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/traveller…

No fix yet
Fix from $1,950 2022-11-03
Frauscher Diagnostic System 102 CRITICAL 9.8
CVE-2022-3575

Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using…

Mitigation only
Fix from $2,300 2022-11-02
Vehicle Booking System HIGH 7.2
CVE-2022-43083

An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a craft…

No fix yet
Fix from $1,950 2022-11-01
Restaurant Pos System HIGH 7.2
CVE-2022-43085

An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP …

No fix yet
Fix from $1,950 2022-11-01
Hubshare HIGH 7.5
CVE-2022-39019

Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the a…

Fix: 3.3.11.3+
Fix from $1,950 2022-10-31
Formalms HIGH 8.8
CVE-2022-41681

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es…

Fix: 3.2.1+
Fix from $1,950 2022-10-31
Formalms HIGH 8.8
CVE-2022-42925

There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es…

Fix: 3.2.1+
Fix from $1,950 2022-10-31
Clinic\'s Patient Management System CRITICAL 9.8
CVE-2022-40471EPSS 20%

Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functio…

No fix yet
Fix from $2,300 2022-10-31
Easyiicms CRITICAL 9.8
CVE-2022-3771

A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php …

Mitigation only
Fix from $2,300 2022-10-31
Wabt MEDIUM 5.5
CVE-2022-43283

wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.

No fix yet
Fix from $1,600 2022-10-28
Canteen Management System HIGH 7.2
CVE-2022-43231

Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerabilit…

No fix yet
Fix from $1,950 2022-10-28
Opennebula HIGH 7.5
CVE-2022-37426

Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

Fix: 6.4.2+
Fix from $1,950 2022-10-28
Canteen Management System HIGH 7.2
CVE-2022-43275

Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This…

No fix yet
Fix from $1,950 2022-10-28
Foreseer Electrical Power Monitoring System CRITICAL 9.8
CVE-2022-33859

A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in…

Fix: 7.6+
Fix from $2,300 2022-10-28
C200 Firmware CRITICAL 10.0
CVE-2021-38397

Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely ex…

Mitigation only
Fix from $2,300 2022-10-28
Online Pet Shop We App HIGH 7.2
CVE-2022-39977

Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulner…

No fix yet
Fix from $1,950 2022-10-27
Online Pet Shop We App HIGH 7.2
CVE-2022-39978

Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. Thi…

No fix yet
Fix from $1,950 2022-10-27
Badaso CRITICAL 9.8
CVE-2022-41711

Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the applica…

No fix yet
Fix from $2,300 2022-10-25
Micollab CRITICAL 9.8
CVE-2022-36452

A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious fil…

Fix: 9.6+
Fix from $2,300 2022-10-25
Gin Vue Admin CRITICAL 9.8
CVE-2022-39305

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 co…

Fix: 2.5.4b+
Fix from $2,300 2022-10-24
Emlog HIGH 7.2
CVE-2022-42189

Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.

No fix yet
Fix from $1,950 2022-10-21
Simple Exam Reviewer Management System HIGH 8.8
CVE-2022-42198

In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.

No fix yet
Fix from $1,950 2022-10-20
Simple Exam Reviewer Management System HIGH 7.2
CVE-2022-42201

Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

No fix yet
Fix from $1,950 2022-10-20
Eve Ng HIGH 7.2
CVE-2022-31366

An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitr…

No fix yet
Fix from $1,950 2022-10-20
Sra Admin MEDIUM 5.4
CVE-2022-39301

sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting …

Fix: after 1.1.1
Fix from $1,600 2022-10-19
Online Tours \& Travels Management System HIGH 7.2
CVE-2022-41537

Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/pro…

No fix yet
Fix from $1,950 2022-10-18
Billing System HIGH 7.2
CVE-2022-41504

An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute a…

No fix yet
Fix from $1,950 2022-10-18