Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.0 CVE-2022-1752 Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2. Trudesk 1.2.2+ Fix from $1,9502022-05-21 CRITICAL 9.8 CVE-2022-30887EPSS 26% Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.… Pharmacy Management System No fix yet Fix from $2,3002022-05-20 CRITICAL 9.8 CVE-2022-28104 Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability. Pdf Editor No fix yet Fix from $2,3002022-05-20 CRITICAL 9.8 CVE-2022-28927EPSS 34% A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters. Subconverter Patch available Fix from $2,3002022-05-19 HIGH 7.2 CVE-2021-41938 An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations. Shopxo No fix yet Fix from $1,9502022-05-19 MEDIUM 6.5 CVE-2022-22482 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files th… Sterling B2b Integrator after 6.1.1.0 Fix from $1,6002022-05-17 HIGH 7.2 CVE-2022-30007 GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content an… Gxcms No fix yet Fix from $1,9502022-05-17 HIGH 7.2 CVE-2022-1409 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as admi… Hotel Booking Engine \& Pms 1.5.8+ Fix from $1,9502022-05-16 HIGH 7.2 CVE-2021-25119 The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allow… Automatic Grid Image Listing after 1.0 Fix from $1,9502022-05-16 HIGH 8.8 CVE-2022-1103EPSS 16% The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could… Advanced Uploader after 4.2 Fix from $1,9502022-05-16 CRITICAL 9.8 CVE-2022-29622 An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parti… Formidable No fix yet Fix from $2,3002022-05-16 HIGH 7.8 CVE-2022-29623 An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a… Connect Multiparty No fix yet Fix from $1,9502022-05-16 CRITICAL 9.8 CVE-2022-29351 An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG f… Tiddlywiki5 Mitigation only Fix from $2,3002022-05-16 CRITICAL 9.8 CVE-2022-29353 An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted f… Graphql Upload No fix yet Fix from $2,3002022-05-16 CRITICAL 9.8 CVE-2022-29354 An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file. Keystone No fix yet Fix from $2,3002022-05-16 HIGH 7.5 CVE-2021-33009 mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system. Mypro 8.20.0+ Fix from $1,9502022-05-13 CRITICAL 9.8 CVE-2021-42967 Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an … Novel Plus No fix yet Fix from $2,3002022-05-13 HIGH 7.6 CVE-2021-27771 User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal m… Sametime Mitigation only Fix from $1,9502022-05-12 HIGH 8.1 CVE-2022-21809 A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can l… Inrouter302 Firmware after 3.5.37 Fix from $1,9502022-05-12 CRITICAL 9.8 CVE-2022-30448 Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php. Hospital Management System No fix yet Fix from $2,3002022-05-11 HIGH 7.2 CVE-2022-29318 An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a … Car Rental Management System No fix yet Fix from $1,9502022-05-11 HIGH 7.2 CVE-2022-29655 An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a… Wedding Management System No fix yet Fix from $1,9502022-05-11 HIGH 7.2 CVE-2020-19228 An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files. Bludit No fix yet Fix from $1,9502022-05-11 CRITICAL 10.0 CVE-2021-42645 CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" paramete… Cmsimple Xh Mitigation only Fix from $2,3002022-05-10 CRITICAL 9.8 CVE-2022-28120 Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerabil… Open Virtual Simulation Experiment Teaching Management Platform No fix yet Fix from $2,3002022-05-05 CRITICAL 9.8 CVE-2022-28606 An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker t… Bosscms Mitigation only Fix from $2,3002022-05-05 MEDIUM 6.1 CVE-2022-1411 Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able … Yetiforce Customer Relationship Management 6.4.0+ Fix from $1,6002022-05-05 CRITICAL 9.8 CVE-2022-28568 Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obt… Simple Doctor\'s Appointment System Mitigation only Fix from $2,3002022-05-04 CRITICAL 9.8 CVE-2022-29347 An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file. Web\@rchiv Mitigation only Fix from $2,3002022-05-04 HIGH 7.2 CVE-2022-29001 In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability Springbootmovie after 1.2 Fix from $1,9502022-05-03