Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Zgr Tps200 Ng Firmware CRITICAL 9.1
CVE-2020-8974

In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows a…

Mitigation only
Fix from $2,300 2022-10-17
Boxbilling HIGH 7.2
CVE-2022-3552EPSS 44%

Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.

Fix: 0.0.1+
Fix from $1,950 2022-10-17
Gin Vue Admin CRITICAL 9.0
CVE-2022-32176

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through th…

Fix: after 2.5.3b
Fix from $2,300 2022-10-17
Chamilo HIGH 8.8
CVE-2022-42029

Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'…

Mitigation only
Fix from $1,950 2022-10-17
74cmsse CRITICAL 9.8
CVE-2022-42154

An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a c…

No fix yet
Fix from $2,300 2022-10-17
Simple Cold Storage Management System HIGH 7.2
CVE-2022-3549

A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unkn…

Mitigation only
Fix from $1,950 2022-10-17
Gin Vue Admin CRITICAL 9.0
CVE-2022-32177

In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through…

Fix: after 2.5.2
Fix from $2,300 2022-10-14
Wedding Planner HIGH 8.8
CVE-2022-41538

Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. …

No fix yet
Fix from $1,950 2022-10-14
Wedding Planner HIGH 8.8
CVE-2022-41539

Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allow…

No fix yet
Fix from $1,950 2022-10-14
Online Diagnostic Lab Management System HIGH 7.2
CVE-2022-41533

Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProdu…

No fix yet
Fix from $1,950 2022-10-13
Online Diagnostic Lab Management System HIGH 7.2
CVE-2022-41534

Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrd…

No fix yet
Fix from $1,950 2022-10-13
Human Resource Management System CRITICAL 9.8
CVE-2022-3458

A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is a…

Mitigation only
Fix from $2,300 2022-10-12
Dedecms HIGH 7.2
CVE-2022-40921

DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.

No fix yet
Fix from $1,950 2022-10-12
Church Management System HIGH 7.2
CVE-2022-41406

An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary c…

No fix yet
Fix from $1,950 2022-10-12
Email Marketer HIGH 8.8
CVE-2022-40777

Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can …

Fix: after 6.5.0
Fix from $1,950 2022-10-11
D8s Algorithms CRITICAL 9.8
CVE-2022-42040EPSS 5%

The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor i…

No fix yet
Fix from $2,300 2022-10-11
D8s Xml CRITICAL 9.8
CVE-2022-42043

The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the d…

No fix yet
Fix from $2,300 2022-10-11
D8s Asns CRITICAL 9.8
CVE-2022-42044

The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the …

No fix yet
Fix from $2,300 2022-10-11
D8s Yaml CRITICAL 9.8
CVE-2022-41380

The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the …

No fix yet
Fix from $2,300 2022-10-11
D8s Utility CRITICAL 9.8
CVE-2022-41381

The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is t…

No fix yet
Fix from $2,300 2022-10-11
D8s Json CRITICAL 9.8
CVE-2022-41382

The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the …

No fix yet
Fix from $2,300 2022-10-11
D8s Archives CRITICAL 9.8
CVE-2022-41383

The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is …

No fix yet
Fix from $2,300 2022-10-11
D8s Domains CRITICAL 9.8
CVE-2022-41384

The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is t…

No fix yet
Fix from $2,300 2022-10-11
D8s Html CRITICAL 9.8
CVE-2022-41385

The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the …

No fix yet
Fix from $2,300 2022-10-11
D8s Utility CRITICAL 9.8
CVE-2022-41386

The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is t…

No fix yet
Fix from $2,300 2022-10-11
D8s Pdfs CRITICAL 9.8
CVE-2022-41387

The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the …

No fix yet
Fix from $2,300 2022-10-11
D8s Urls CRITICAL 9.8
CVE-2022-42036

The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the …

No fix yet
Fix from $2,300 2022-10-11
D8s Asns CRITICAL 9.8
CVE-2022-42037

The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the …

No fix yet
Fix from $2,300 2022-10-11
D8s Ip Addresses CRITICAL 9.8
CVE-2022-42038

The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor…

No fix yet
Fix from $2,300 2022-10-11
D8s Lists CRITICAL 9.8
CVE-2022-42039

The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the…

No fix yet
Fix from $2,300 2022-10-11