Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Inventree HIGH 8.8
CVE-2022-2111

Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

Fix: 0.7.2+
Fix from $1,950 2022-06-17
Advanced School Management System HIGH 7.2
CVE-2022-32433

itsourcecode Advanced School Management System v1.0 is vulnerable to Arbitrary code execution via ip/school/view/all_teacher.php.

No fix yet
Fix from $1,950 2022-06-15
Monstra CRITICAL 9.8
CVE-2021-40940

Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

Fix: after 3.0.4
Fix from $2,300 2022-06-15
Kreasfero CRITICAL 9.8
CVE-2021-42675

Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code exe…

Mitigation only
Fix from $2,300 2022-06-14
Open Forms MEDIUM 6.5
CVE-2022-31041

Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields c…

Fix: 1.0.9+
Fix from $1,600 2022-06-13
Wp Svg Icons HIGH 7.2
CVE-2022-0863EPSS 24%

The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin…

Fix: after 3.2.3
Fix from $1,950 2022-06-13
Solar Log 250 Firmware CRITICAL 9.8
CVE-2017-20021

A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component Fil…

No fix yet
Fix from $2,300 2022-06-09
Txpert Hub Coretec 4 Firmware MEDIUM 6.7
CVE-2021-35532

A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or mal…

Mitigation only
Fix from $1,600 2022-06-07
Fudforum HIGH 7.2
CVE-2022-30860EPSS 24%

FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.

Fix: 3.1.2+
Fix from $1,950 2022-06-06
Car Rental Management System CRITICAL 9.8
CVE-2022-32019

Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.

No fix yet
Fix from $2,300 2022-06-02
Ngeniusone HIGH 8.8
CVE-2021-45982

NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.

Mitigation only
Fix from $1,950 2022-06-02
Elite Cms CRITICAL 9.8
CVE-2022-30808EPSS 17%

elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.

No fix yet
Fix from $2,300 2022-06-02
Wedding Management System HIGH 8.8
CVE-2022-30819

In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.

No fix yet
Fix from $1,950 2022-06-02
Wedding Management System HIGH 8.8
CVE-2022-30820

In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.

No fix yet
Fix from $1,950 2022-06-02
Wedding Management System HIGH 8.8
CVE-2022-30821

In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vul…

No fix yet
Fix from $1,950 2022-06-02
Wedding Management System HIGH 8.8
CVE-2022-30822

In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.

No fix yet
Fix from $1,950 2022-06-02
Mcms CRITICAL 9.8
CVE-2022-30506

An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.

No fix yet
Fix from $2,300 2022-06-02
Merchandise Online Store CRITICAL 9.8
CVE-2022-30423

Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system informa…

No fix yet
Fix from $2,300 2022-06-02
Witycms HIGH 8.8
CVE-2022-29725

An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2022-06-02
Tpcms HIGH 8.8
CVE-2022-29624

An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2022-06-02
Aceweb Online Portal HIGH 7.5
CVE-2022-24581

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading…

Fix: 3.5.065+
Fix from $1,950 2022-06-02
Aceweb Online Portal CRITICAL 9.8
CVE-2022-24239

ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.

Fix: 3.5.068+
Fix from $2,300 2022-06-02
Maxboard CRITICAL 9.8
CVE-2021-26634

SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromis…

Fix: 1.9.6+
Fix from $2,300 2022-06-02
Archer HIGH 7.5
CVE-2021-33615

RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.

Fix: 6.9.3.4 / 6.10.0.2+
Fix from $1,950 2022-06-02
Roncoo Education CRITICAL 9.8
CVE-2022-29632EPSS 17%

An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code …

No fix yet
Fix from $2,300 2022-05-26
Mindoc HIGH 7.8
CVE-2022-29637

An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file.

No fix yet
Fix from $1,950 2022-05-26
Online Food Ordering System HIGH 7.2
CVE-2022-29651

An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2022-05-25
Siteserver Cms CRITICAL 9.8
CVE-2021-42654

SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

Fix: 5.1+
Fix from $2,300 2022-05-24
Home Clean Services Management System HIGH 7.2
CVE-2022-1837

A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=re…

No fix yet
Fix from $1,950 2022-05-24
Publify MEDIUM 5.4
CVE-2022-1811

Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

Fix: 9.2.9+
Fix from $1,600 2022-05-23