Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Gym Management System HIGH 8.8
CVE-2022-2749

A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown fun…

No fix yet
Fix from $1,950 2022-08-11
Company Website Cms CRITICAL 9.8
CVE-2022-2750

A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dash…

Mitigation only
Fix from $2,300 2022-08-11
Company Website Cms CRITICAL 9.8
CVE-2022-2751

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of t…

Mitigation only
Fix from $2,300 2022-08-11
Company Website Cms CRITICAL 9.8
CVE-2022-2736

A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashbo…

Mitigation only
Fix from $2,300 2022-08-11
Company Website Cms CRITICAL 9.8
CVE-2022-2740

A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the fil…

Mitigation only
Fix from $2,300 2022-08-11
Gym Management System CRITICAL 9.8
CVE-2022-2744

A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown fun…

Mitigation only
Fix from $2,300 2022-08-11
Simple Online Book Store System CRITICAL 9.8
CVE-2022-2746

A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code …

Mitigation only
Fix from $2,300 2022-08-11
Ucms CRITICAL 9.8
CVE-2022-35426

UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.

No fix yet
Fix from $2,300 2022-08-10
Airspot 5410 Firmware CRITICAL 9.1
CVE-2022-36264

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriti…

Fix: after 0.3.4.1-4
Fix from $2,300 2022-08-08
User Private Files HIGH 8.8
CVE-2022-2356

The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, whic…

Fix: 1.1.3+
Fix from $1,950 2022-08-08
Company Website Cms HIGH 8.8
CVE-2022-2694

A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulat…

No fix yet
Fix from $1,950 2022-08-06
Alphaware E Commerce System HIGH 8.8
CVE-2022-2678

A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown …

No fix yet
Fix from $1,950 2022-08-05
Jeecg Boot CRITICAL 9.8
CVE-2022-2647

A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /api/. The manipulatio…

Mitigation only
Fix from $2,300 2022-08-04
Mealie CRITICAL 9.8
CVE-2022-34613

Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $2,300 2022-08-02
Enable Svg\, Webp \& Ico Upload HIGH 8.8
CVE-2022-34154

Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPr…

Fix: after 1.0.1
Fix from $1,950 2022-08-01
Hiby R3 Pro Firmware CRITICAL 9.8
CVE-2022-34496

Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.

Fix: after 1.7
Fix from $2,300 2022-07-29
Open Source Point Of Sale HIGH 7.2
CVE-2022-34578

Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

No fix yet
Fix from $1,950 2022-07-28
Barangay Management System HIGH 7.2
CVE-2022-34120EPSS 18%

Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activ…

No fix yet
Fix from $1,950 2022-07-27
Sims HIGH 8.8
CVE-2022-34549

Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to e…

No fix yet
Fix from $1,950 2022-07-27
Feehi Cms HIGH 8.8
CVE-2022-34971

An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a craf…

No fix yet
Fix from $1,950 2022-07-27
Open Source Social Network HIGH 7.2
CVE-2022-34965

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/admi…

No fix yet
Fix from $1,950 2022-07-25
Dataease CRITICAL 9.8
CVE-2022-34115

DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

Patch available
Fix from $2,300 2022-07-22
Givewp HIGH 7.2
CVE-2022-28700

Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

Fix: 2.21.0+
Fix from $1,950 2022-07-21
Barangay Management System HIGH 7.2
CVE-2022-34024

Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pa…

No fix yet
Fix from $1,950 2022-07-19
Wp All Import HIGH 7.2
CVE-2022-1565EPSS 15%

The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in version…

Fix: 3.6.8+
Fix from $1,950 2022-07-18
Dsknet HIGH 8.8
CVE-2022-24688

An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Exec…

No fix yet
Fix from $1,950 2022-07-18
Octobot CRITICAL 9.8
CVE-2021-36711EPSS 16%

WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.

Fix: 0.4.4+
Fix from $2,300 2022-07-16
Roxy Wi CRITICAL 9.8
CVE-2022-31161EPSS 27%

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-15
School Erp Pro HIGH 8.8
CVE-2022-32119

Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.ph…

Mitigation only
Fix from $1,950 2022-07-15
Microweber HIGH 8.8
CVE-2021-36461

An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by upload…

No fix yet
Fix from $1,950 2022-07-15