Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Urve Web Manager HIGH 8.0
CVE-2022-2419EPSS 13%

A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collec…

No fix yet
Fix from $1,950 2022-07-15
Urve Web Manager HIGH 8.0
CVE-2022-2420

A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/upload…

No fix yet
Fix from $1,950 2022-07-15
Urve Web Manager HIGH 8.0
CVE-2022-2418

A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.…

No fix yet
Fix from $1,950 2022-07-15
Lvskihp Indoorunit Firmware CRITICAL 9.8
CVE-2022-28369

Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation o…

No fix yet
Fix from $2,300 2022-07-14
Lvskihp Indoorunit Firmware HIGH 7.5
CVE-2022-28372

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a means of pr…

No fix yet
Fix from $1,950 2022-07-14
Strapi HIGH 8.8
CVE-2022-32114

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF f…

No fix yet
Fix from $1,950 2022-07-13
Windows 10 HIGH 8.8
CVE-2022-30216EPSS 89%

Windows Server Service Tampering Vulnerability

No fix yet
Fix from $1,950 2022-07-12
Clinic\'s Patient Management System HIGH 8.8
CVE-2022-2297

A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function…

No fix yet
Fix from $1,950 2022-07-12
Easync CRITICAL 9.8
CVE-2022-1952EPSS 23%

The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads t…

Fix: 1.1.16+
Fix from $2,300 2022-07-11
Archiver CRITICAL 9.8
CVE-2021-29281

File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affect…

Fix: 15.2+
Fix from $2,300 2022-07-07
Codoforum HIGH 7.2
CVE-2022-31854EPSS 32%

Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.

No fix yet
Fix from $1,950 2022-07-07
Nextgen Gallery HIGH 8.8
CVE-2015-1784

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica…

Fix: 2.0.77.3+
Fix from $1,950 2022-07-07
Nextgen Gallery MEDIUM 6.5
CVE-2015-1785

In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica…

Fix: 2.0.77.3+
Fix from $1,600 2022-07-07
Dice CRITICAL 9.8
CVE-2022-32413

An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.

No fix yet
Fix from $2,300 2022-07-05
Wp All Import HIGH 7.2
CVE-2022-2268

The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the …

Fix: 3.6.8+
Fix from $1,950 2022-07-04
Mcms CRITICAL 9.8
CVE-2022-31943

MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

No fix yet
Fix from $2,300 2022-07-01
Nucleus Cms HIGH 7.2
CVE-2021-37770

Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without …

No fix yet
Fix from $1,950 2022-06-30
Halo CRITICAL 9.8
CVE-2022-32994EPSS 18%

Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.

No fix yet
Fix from $2,300 2022-06-27
Debian Linux HIGH 8.8
CVE-2022-31086

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Library Management System HIGH 8.8
CVE-2022-2212

A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the…

No fix yet
Fix from $1,950 2022-06-27
Cognos Analytics CRITICAL 9.8
CVE-2021-38945

IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X…

Fix: 11.1.7+
Fix from $2,300 2022-06-24
Sepcos Control And Protection Relay Firmware HIGH 7.5
CVE-2022-2102

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response…

Fix: 1.23.21 / 1.24.8+
Fix from $1,950 2022-06-24
Local Run Manager CRITICAL 9.8
CVE-2022-1519

LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executab…

Fix: after 3.1
Fix from $2,300 2022-06-24
User Photo HIGH 8.8
CVE-2013-1916EPSS 13%

In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server …

Patch available
Fix from $1,950 2022-06-24
Docebo HIGH 8.8
CVE-2022-31362EPSS 18%

Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects pro…

Fix: after 4.0.5
Fix from $1,950 2022-06-23
Laiketui CRITICAL 9.8
CVE-2021-40954

Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

No fix yet
Fix from $2,300 2022-06-23
Sv Cpt Mc310 Firmware CRITICAL 9.8
CVE-2022-31374

An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted …

No fix yet
Fix from $2,300 2022-06-21
Trudesk CRITICAL 9.8
CVE-2022-2128

Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.

Fix: 1.2.4+
Fix from $2,300 2022-06-20
Allow Svg Files HIGH 7.2
CVE-2022-1939

The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to up…

Fix: 1.1+
Fix from $1,950 2022-06-20
Elefant Cms HIGH 8.8
CVE-2017-20063

A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/uplo…

No fix yet
Fix from $1,950 2022-06-20