Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2024-12233 A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of th… Online Notice Board No fix yet Fix from $2,3002024-12-05 HIGH 8.8 CVE-2024-51548 Dangerous File Upload vulnerabilities allow upload of malicious scripts.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.… Aspect Ent 12 Firmware 3.08.03+ Fix from $1,9502024-12-05 HIGH 8.7 CVE-2024-53982 ZOO-Project is a C-based WPS (Web Processing Service) implementation. A path traversal vulnerability was discovered in Zoo-Project Echo example. The … Patch available Fix from $1,9502024-12-04 CRITICAL 9.8 CVE-2024-40744 Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8. Convert Forms 4.4.8+ Fix from $2,3002024-12-04 HIGH 8.8 CVE-2024-46625 An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute… Mitigation only Fix from $1,9502024-12-03 CRITICAL 9.8 CVE-2024-25020 IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Jou… Cognos Controller Mitigation only Fix from $2,3002024-12-03 CRITICAL 9.1 CVE-2024-53863 Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially cra… Synapse 1.120.1+ Fix from $2,3002024-12-03 CRITICAL 9.8 CVE-2024-40691 IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web … Cognos Controller Mitigation only Fix from $2,3002024-12-03 CRITICAL 9.8 CVE-2024-25019 IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry a… Cognos Controller Mitigation only Fix from $2,3002024-12-03 HIGH 7.5 CVE-2024-11391 The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connect… Advanced File Manager 5.2.11+ Fix from $1,9502024-12-03 HIGH 7.2 CVE-2024-53564 A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege a… Freepbx Mitigation only Fix from $1,9502024-12-02 CRITICAL 10.0 CVE-2024-52476 Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web … Mitigation only Fix from $2,3002024-12-02 CRITICAL 9.8 CVE-2024-11979 DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote at… Mitigation only Fix from $2,3002024-11-29 MEDIUM 5.4 CVE-2024-11971 A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functiona… Jpress No fix yet Fix from $1,6002024-11-28 CRITICAL 10.0 CVE-2024-52490 Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web Shell to a Web Server.This i… Mitigation only Fix from $2,3002024-11-28 CRITICAL 9.9 CVE-2024-11082 The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_pan… Patch available Fix from $2,3002024-11-28 HIGH 8.8 CVE-2024-8066 The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function … Filester 1.8.7+ Fix from $1,9502024-11-28 MEDIUM 6.3 CVE-2024-53619 An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading … Spip No fix yet Fix from $1,6002024-11-26 HIGH 7.2 CVE-2024-9504 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio… Mitigation only Fix from $1,9502024-11-26 HIGH 8.8 CVE-2024-11674 A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file… Hospital Management System No fix yet Fix from $1,9502024-11-26 CRITICAL 9.8 CVE-2024-11661 A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic. This vulnerability affects u… Free Exam Hall Seating Management System No fix yet Fix from $2,3002024-11-25 HIGH 8.8 CVE-2024-9660 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj… School Management System 92.0.0+ Fix from $1,9502024-11-23 CRITICAL 9.8 CVE-2024-9942 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the M… Wordpress Gym Management System 67.2.0+ Fix from $2,3002024-11-23 CRITICAL 9.8 CVE-2024-9659 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj… School Management System 92.0.0+ Fix from $2,3002024-11-23 HIGH 8.8 CVE-2024-51364 An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file. No fix yet Fix from $1,9502024-11-21 CRITICAL 9.8 CVE-2024-51366 An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a cr… Mitigation only Fix from $2,3002024-11-21 CRITICAL 10.0 CVE-2024-8525 An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execu… Mitigation only Fix from $2,3002024-11-21 CRITICAL 9.8 CVE-2024-52677 HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php. Hkcms after 2.3.2.240702 Fix from $2,3002024-11-20 HIGH 7.2 CVE-2024-52769 An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploa… Dedebiz No fix yet Fix from $1,9502024-11-20 HIGH 7.2 CVE-2024-51208 File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script… Boat Booking System Mitigation only Fix from $1,9502024-11-20