Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
D8s Archives CRITICAL 9.8
CVE-2022-38881

The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the demo…

No fix yet
Fix from $2,300 2022-09-19
D8s Json CRITICAL 9.8
CVE-2022-38882

The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democrit…

No fix yet
Fix from $2,300 2022-09-19
D8s Math CRITICAL 9.8
CVE-2022-38883

The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democrit…

No fix yet
Fix from $2,300 2022-09-19
D8s Grammars CRITICAL 9.8
CVE-2022-38884

The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the demo…

No fix yet
Fix from $2,300 2022-09-19
D8s Netstrings CRITICAL 9.8
CVE-2022-38885

The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the de…

No fix yet
Fix from $2,300 2022-09-19
D8s Xml CRITICAL 9.8
CVE-2022-38886

The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritu…

No fix yet
Fix from $2,300 2022-09-19
D8s Python CRITICAL 9.8
CVE-2022-38887

The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings pac…

No fix yet
Fix from $2,300 2022-09-19
Garage Management System HIGH 7.2
CVE-2022-38877

Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id=1.

No fix yet
Fix from $1,950 2022-09-16
Espocrm HIGH 8.8
CVE-2022-38843

EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any extension to the server. Attacke…

No fix yet
Fix from $1,950 2022-09-16
Event Management System HIGH 7.2
CVE-2022-38323

Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This v…

No fix yet
Fix from $1,950 2022-09-15
Paymoney HIGH 8.0
CVE-2022-37140

PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket function and upload the malicious…

No fix yet
Fix from $1,950 2022-09-14
Garage Management System HIGH 8.8
CVE-2022-36667EPSS 24%

Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnera…

No fix yet
Fix from $1,950 2022-09-14
Aerocms HIGH 8.8
CVE-2022-38305

AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attac…

No fix yet
Fix from $1,950 2022-09-13
Cuppacms CRITICAL 9.8
CVE-2022-38296

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

No fix yet
Fix from $2,300 2022-09-12
Anydesk HIGH 8.8
CVE-2021-44426

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is …

Fix: 6.2.6 / 6.3.3+
Fix from $1,950 2022-09-12
Online Driving School Project CRITICAL 9.8
CVE-2022-3129

A vulnerability was found in codeprojects Online Driving School. It has been rated as critical. Affected by this issue is some unknown functionality …

No fix yet
Fix from $2,300 2022-09-07
Feehicms CRITICAL 9.8
CVE-2020-21516

There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.

Patch available
Fix from $2,300 2022-09-06
Online Ordering System HIGH 7.2
CVE-2022-36580

An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers t…

No fix yet
Fix from $1,950 2022-08-31
Garage Management System HIGH 7.2
CVE-2022-36582

An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute ar…

No fix yet
Fix from $1,950 2022-08-31
Garage Management System HIGH 8.8
CVE-2022-37184

The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can …

No fix yet
Fix from $1,950 2022-08-31
Skybridge Mb A100 Firmware CRITICAL 9.8
CVE-2022-36557

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This …

Fix: after 4.2.0
Fix from $2,300 2022-08-29
Claroline CRITICAL 9.8
CVE-2022-37159EPSS 25%

Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

Fix: after 13.5.7
Fix from $2,300 2022-08-25
Wukong Crm CRITICAL 9.8
CVE-2022-37181

72crm 9.0 has an Arbitrary file upload vulnerability.

No fix yet
Fix from $2,300 2022-08-24
Uploading Svg\, Webp And Ico Files HIGH 7.2
CVE-2022-36285

Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.

Fix: after 1.0.1
Fix from $1,950 2022-08-23
Baijiacms CRITICAL 9.8
CVE-2022-35150

Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.

No fix yet
Fix from $2,300 2022-08-22
Advanced Custom Fields HIGH 8.8
CVE-2022-2594

The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to …

Fix: 5.12.3+
Fix from $1,950 2022-08-22
Simple And Nice Shopping Cart Script HIGH 8.8
CVE-2022-2909

A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is…

No fix yet
Fix from $1,950 2022-08-20
Greyd.suite CRITICAL 9.8
CVE-2022-2180

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allo…

Fix: 1.2.7+
Fix from $2,300 2022-08-15
Zoo Management System CRITICAL 9.8
CVE-2022-2804

A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /p…

No fix yet
Fix from $2,300 2022-08-12
Gas Agency Management System CRITICAL 9.8
CVE-2022-2779

A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulnerability is an unknown functio…

No fix yet
Fix from $2,300 2022-08-12