Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.8 CVE-2024-47423 Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could resu… Framemaker 2020.7 / 2022.5+ Fix from $1,9502024-10-09 HIGH 7.8 CVE-2024-45136 InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitr… Incopy 18.5.4 / 19.5+ Fix from $1,9502024-10-09 HIGH 7.8 CVE-2024-45137 InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result… Indesign 18.5.4 / 19.5+ Fix from $1,9502024-10-09 CRITICAL 9.8 CVE-2024-47823 Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and … Livewire 2.12.7 / 3.5.2+ Fix from $2,3002024-10-08 MEDIUM 6.5 CVE-2024-37179 SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting… Businessobjects Business Intelligence Mitigation only Fix from $1,6002024-10-08 HIGH 8.0 CVE-2024-47319 Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form bit-form.This issue affects Bit Form: from n/a through <= 2.13.10. Mitigation only Fix from $1,9502024-10-05 MEDIUM 6.1 CVE-2024-9417 The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in th… Hash Form 1.2.0+ Fix from $1,6002024-10-05 MEDIUM 6.8 CVE-2024-8743 The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript Fi… Mitigation only Fix from $1,6002024-10-05 HIGH 8.8 CVE-2024-37868 File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply… Online Discussion Forum No fix yet Fix from $1,9502024-10-04 HIGH 8.8 CVE-2024-37869 File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.ph… Online Discussion Forum No fix yet Fix from $1,9502024-10-04 HIGH 8.8 CVE-2024-47655 This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An au… Client Dashboard 9.7.0+ Fix from $1,9502024-10-04 MEDIUM 5.4 CVE-2024-45965 Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5… Contao 4.13.54 / 5.3.30+ Fix from $1,6002024-10-02 HIGH 8.8 CVE-2024-7855EPSS 18% The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function… Wp Hotel Booking 2.1.3+ Fix from $1,9502024-10-02 CRITICAL 9.8 CVE-2024-9108 The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remotei… Mitigation only Fix from $2,3002024-10-01 HIGH 8.8 CVE-2024-46441 An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/… Mitigation only Fix from $1,9502024-09-27 CRITICAL 9.8 CVE-2024-9280 A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability a… Kvf Admin Mitigation only Fix from $2,3002024-09-27 HIGH 8.8 CVE-2024-47169 Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attac… Agnai 1.0.330+ Fix from $1,9502024-09-26 HIGH 8.8 CVE-2024-8126 The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, … Advanced File Manager 5.2.9+ Fix from $1,9502024-09-26 MEDIUM 5.4 CVE-2024-8725 Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ens… Advanced File Manager 5.2.9+ Fix from $1,6002024-09-26 CRITICAL 9.8 CVE-2024-7772 The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function i… Jupiter X Core 4.6.6+ Fix from $2,3002024-09-26 CRITICAL 9.8 CVE-2024-8940 Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plu… Scriptcase Mitigation only Fix from $2,3002024-09-25 CRITICAL 9.8 CVE-2023-26686 File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a… Cs Cart Multivendor No fix yet Fix from $2,3002024-09-25 HIGH 8.8 CVE-2023-26690 File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor… Cs Cart Multivendor No fix yet Fix from $1,9502024-09-25 CRITICAL 9.8 CVE-2024-46101 GDidees CMS <= v3.9.1 has a file upload vulnerability. Gdidees Cms after 3.9.1 Fix from $2,3002024-09-20 MEDIUM 6.3 CVE-2024-9036 A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file… Online Book Store Project No fix yet Fix from $1,6002024-09-20 CRITICAL 9.8 CVE-2024-9038 A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionalit… Online Shopping Portal No fix yet Fix from $2,3002024-09-20 CRITICAL 9.8 CVE-2024-40125 An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitr… Cless Server No fix yet Fix from $2,3002024-09-19 HIGH 8.8 CVE-2024-46373 Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend. Dedecms Mitigation only Fix from $1,9502024-09-18 CRITICAL 9.8 CVE-2024-46377 Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_clas… Best House Rental Management System Mitigation only Fix from $2,3002024-09-18 HIGH 8.8 CVE-2024-45398 Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the… Contao 4.13.49 / 5.3.15+ Fix from $1,9502024-09-17