Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2024-10420 A vulnerability classified as critical has been found in SourceCodester Attendance and Payroll System 1.0. This affects the function upload of the fi… Attendance And Payroll System Mitigation only Fix from $2,3002024-10-27 CRITICAL 9.8 CVE-2024-10413 A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is th… Online Hotel Reservation System Mitigation only Fix from $2,3002024-10-27 HIGH 7.2 CVE-2024-10410 A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the functio… Online Hotel Reservation System No fix yet Fix from $1,9502024-10-27 CRITICAL 9.8 CVE-2024-9932EPSS 36% The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNe… Mitigation only Fix from $2,3002024-10-26 HIGH 8.8 CVE-2024-37847 An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted fi… Mango 4.5.5 / 5.1.4+ Fix from $1,9502024-10-25 HIGH 8.8 CVE-2024-45263 An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uplo… Mt6000 Firmware 4.6.4+ Fix from $1,9502024-10-24 HIGH 7.2 CVE-2024-48454 An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component Purchase Order Management System Mitigation only Fix from $1,9502024-10-24 MEDIUM 6.6 CVE-2024-49676 Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor custom-icons-for-elementor allows Upload a… Mitigation only Fix from $1,6002024-10-23 CRITICAL 9.9 CVE-2024-49671 Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featured Images – AI Postpix ai-po… Mitigation only Fix from $2,3002024-10-23 CRITICAL 9.9 CVE-2024-49669 Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Upload a Web Shell to a Web Ser… Mitigation only Fix from $2,3002024-10-23 CRITICAL 9.9 CVE-2024-49652 Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Upload a Web S… Mitigation only Fix from $2,3002024-10-23 CRITICAL 9.9 CVE-2024-49653 Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This is… Mitigation only Fix from $2,3002024-10-23 CRITICAL 9.9 CVE-2024-49658 Unrestricted Upload of File with Dangerous Type vulnerability in ecomerciar Woocommerce Custom Profile Picture woo-custom-profile-picture allows Uplo… Mitigation only Fix from $2,3002024-10-23 CRITICAL 10.0 CVE-2024-49668 Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web S… Mitigation only Fix from $2,3002024-10-23 CRITICAL 9.8 CVE-2024-10293 A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/c… Zzcms Mitigation only Fix from $2,3002024-10-23 CRITICAL 9.8 CVE-2024-10292 A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTab… Zzcms Mitigation only Fix from $2,3002024-10-23 HIGH 8.2 CVE-2024-46482 An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute a… Mitigation only Fix from $1,9502024-10-22 HIGH 8.8 CVE-2024-10201 Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to… Administrative Management System Mitigation only Fix from $1,9502024-10-21 CRITICAL 9.8 CVE-2024-49610 Unrestricted Upload of File with Dangerous Type vulnerability in photokiteditor photokit photokit allows Upload a Web Shell to a Web Server.This issu… Photokit after 1.0 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49330 Unrestricted Upload of File with Dangerous Type vulnerability in brx8r Nice Backgrounds nicebackgrounds allows Upload a Web Shell to a Web Server.Thi… Nice Backgrounds after 1.0 Fix from $2,3002024-10-20 HIGH 8.8 CVE-2024-49331 Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System plms allows Upload a Web Shell to a … Property Lot Management System after 4.2.38 Fix from $1,9502024-10-20 CRITICAL 9.8 CVE-2024-49607 Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows Upload a Web Shell to a Web Se… Wp Dropbox Dropins after 1.0 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49327 Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell to a Web S… Woostagram Connect after 1.0.2 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49329 Unrestricted Upload of File with Dangerous Type vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Upload a Web Shell to a Web Serve… Wp Rest Api Fns after 1.0.0 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49324 Unrestricted Upload of File with Dangerous Type vulnerability in sovratecdev Sovratec Case Management sovratec-case-management allows Upload a Web Sh… Sovratec Case Management after 1.0.0 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49326 Unrestricted Upload of File with Dangerous Type vulnerability in Vasileios Kerasiotis Affiliator affiliator-lite allows Upload a Web Shell to a Web S… Affiliator after 2.1.3 Fix from $2,3002024-10-20 CRITICAL 9.8 CVE-2024-49611 Unrestricted Upload of File with Dangerous Type vulnerability in paxmanpwnz Product Website Showcase product-websites-showcase allows Upload a Web Sh… Product Website Showcase after 1.0 Fix from $2,3002024-10-20 HIGH 8.8 CVE-2024-10161 A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file change-i… Boat Booking System No fix yet Fix from $1,9502024-10-20 CRITICAL 9.8 CVE-2024-10120 A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unknown code of the file /service… Radar after 1.0.8 Fix from $2,3002024-10-18 CRITICAL 10.0 CVE-2024-49314 Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie JiangQie Free Mini Program jiangqie-free-mini-program allows Upload a Web S… Mitigation only Fix from $2,3002024-10-17