Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Wedding Planner HIGH 8.8
CVE-2022-42034

Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.

No fix yet
Fix from $1,950 2022-10-11
Wedding Planner HIGH 8.8
CVE-2022-42229

Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.

No fix yet
Fix from $1,950 2022-10-11
Web Based Student Clearance System HIGH 7.5
CVE-2022-3436

A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unkno…

No fix yet
Fix from $1,950 2022-10-09
Online Leave Management System HIGH 7.2
CVE-2022-41379

An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attacker…

No fix yet
Fix from $1,950 2022-10-07
Backdrop Cms HIGH 7.2
CVE-2022-42092

Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispu…

No fix yet
Fix from $1,950 2022-10-07
Online Diagnostic Lab Management System HIGH 7.2
CVE-2022-41512

An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to …

No fix yet
Fix from $1,950 2022-10-07
Creativedream File Uploader CRITICAL 9.8
CVE-2022-40721

Arbitrary file upload vulnerability in php uploader

No fix yet
Fix from $2,300 2022-10-03
Frontend File Manager HIGH 8.8
CVE-2022-3125

The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary ex…

Fix: 21.3+
Fix from $1,950 2022-10-03
Dedecms HIGH 7.2
CVE-2022-40886

DedeCMS 5.7.98 has a file upload vulnerability in the background.

No fix yet
Fix from $1,950 2022-10-03
Mojoportal HIGH 8.8
CVE-2022-40341

mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG f…

Mitigation only
Fix from $1,950 2022-09-30
Billing System Project HIGH 7.2
CVE-2022-41437

Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php.

No fix yet
Fix from $1,950 2022-09-30
Discourse HIGH 7.2
CVE-2022-36066

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests…

Fix: 2.8.9+
Fix from $1,950 2022-09-29
Chamilo HIGH 8.8
CVE-2022-40407

A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.

No fix yet
Fix from $1,950 2022-09-29
Metersphere CRITICAL 9.8
CVE-2021-45790

An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where atta…

No fix yet
Fix from $2,300 2022-09-29
Flatpress HIGH 7.2
CVE-2022-40048

Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.

No fix yet
Fix from $1,950 2022-09-29
Exam Reviewer Management System HIGH 8.8
CVE-2022-40878EPSS 23%

In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (R…

No fix yet
Fix from $1,950 2022-09-27
Product Image Bulk Upload CRITICAL 9.8
CVE-2022-37346

EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploitin…

Patch available
Fix from $2,300 2022-09-27
Zfile CRITICAL 9.8
CVE-2022-40050

ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.

No fix yet
Fix from $2,300 2022-09-26
Cm Download Manager HIGH 7.2
CVE-2022-3076

The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extensio…

Fix: 2.8.6+
Fix from $1,950 2022-09-26
Zoo Management System HIGH 7.2
CVE-2022-40924

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module i…

No fix yet
Fix from $1,950 2022-09-26
Zoo Management System HIGH 7.2
CVE-2022-40925

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in …

No fix yet
Fix from $1,950 2022-09-26
Mattermost Server MEDIUM 6.5
CVE-2022-3257

Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which a…

Fix: 7.2.0+
Fix from $1,600 2022-09-23
Simple College Website CRITICAL 9.8
CVE-2022-40087

Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability …

No fix yet
Fix from $2,300 2022-09-22
Zoo Management System HIGH 7.2
CVE-2022-40932

In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" mod…

No fix yet
Fix from $1,950 2022-09-22
Wpide HIGH 7.2
CVE-2022-40217

Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.

Fix: after 2.6
Fix from $1,950 2022-09-21
Wp All Import HIGH 7.2
CVE-2022-36386

Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

Fix: after 3.6.7
Fix from $1,950 2022-09-21
Octoprint MEDIUM 5.4
CVE-2022-2872

Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.

Fix: 1.8.3+
Fix from $1,600 2022-09-21
Pagekit CRITICAL 9.8
CVE-2022-38916EPSS 18%

A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files

No fix yet
Fix from $2,300 2022-09-20
D8s Pdfs CRITICAL 9.8
CVE-2022-40431

The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democrit…

No fix yet
Fix from $2,300 2022-09-19
D8s Strings CRITICAL 9.8
CVE-2022-40432

The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democ…

No fix yet
Fix from $2,300 2022-09-19