Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2024-42780 An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows att… Music Management System No fix yet Fix from $1,9502024-08-21 CRITICAL 9.8 CVE-2024-42777 An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attack… Music Management System No fix yet Fix from $2,3002024-08-21 CRITICAL 9.8 CVE-2024-42563 An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file. Erp after 2018-03-02 Fix from $2,3002024-08-20 HIGH 7.2 CVE-2022-1206 The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extens… Mitigation only Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-7944 A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been classified as critical. Affected is the function Update… Laravel Property Management System Mitigation only Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-7943 A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload o… Laravel Property Management System No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-43249 Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form Pro allows Command Injection.This issue affects Bit Form Pro: from… Bit Form after 2.6.4 Fix from $1,9502024-08-19 HIGH 7.2 CVE-2024-7917 A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue is some unknown functionalit… Douphp No fix yet Fix from $1,9502024-08-18 HIGH 7.2 CVE-2024-7910 A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by this issue is some unknown funct… Online Railway Reservation System No fix yet Fix from $1,9502024-08-18 HIGH 8.8 CVE-2024-7906 A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type of the file /admin/dialog/se… Dedebiz Mitigation only Fix from $1,9502024-08-18 HIGH 7.2 CVE-2024-7905 A vulnerability classified as critical has been found in DedeBIZ 6.3.0. This affects the function AdminUpload of the file admin/archives_do.php. The … Dedebiz No fix yet Fix from $1,9502024-08-18 HIGH 8.8 CVE-2024-7904 A vulnerability was found in DedeBIZ 6.3.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/fil… Dedebiz No fix yet Fix from $1,9502024-08-18 HIGH 8.8 CVE-2024-7903 A vulnerability was found in DedeBIZ 6.3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file … Dedebiz No fix yet Fix from $1,9502024-08-18 CRITICAL 9.8 CVE-2023-0714 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions … Metform Elementor Contact Form Builder 3.3.0+ Fix from $2,3002024-08-17 HIGH 8.8 CVE-2024-42676 File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the… Enterprise Resource Management System after 1.0 Fix from $1,9502024-08-15 CRITICAL 9.0 CVE-2024-39397 Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnera… Commerce after 2.4.3 Fix from $2,3002024-08-14 HIGH 8.8 CVE-2024-4389 The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the up… Mitigation only Fix from $1,9502024-08-14 CRITICAL 10.0 CVE-2024-43160 Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6. Mitigation only Fix from $2,3002024-08-13 HIGH 8.8 CVE-2024-6823 The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline… Media Library Assistant 3.19+ Fix from $1,9502024-08-13 MEDIUM 5.3 CVE-2024-7705 A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the function uploadeditor of the… Mwcms Mitigation only Fix from $1,6002024-08-12 CRITICAL 9.8 CVE-2024-38530 The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save… Openeclass 3.16+ Fix from $2,3002024-08-12 HIGH 7.2 CVE-2024-7694 KEV ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on … Threatsonar Anti Ransomware 3.5.0+ Fix from $1,9502024-08-12 CRITICAL 9.8 CVE-2024-7399 KEVEPSS 92% Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to wr… Magicinfo 9 Server 21.1050.0+ Fix from $2,3002024-08-12 CRITICAL 9.8 CVE-2024-41577 An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a c… Mitigation only Fix from $2,3002024-08-12 MEDIUM 5.4 CVE-2024-5226 The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions … Fuse Social Floating Sidebar 5.4.11+ Fix from $1,6002024-08-08 HIGH 8.8 CVE-2024-6707 Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability. Open Webui No fix yet Fix from $1,9502024-08-07 HIGH 8.8 CVE-2024-41913 A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize … Poly Clariti Manager 10.12.0.2_100+ Fix from $1,9502024-08-06 HIGH 8.8 CVE-2024-7506 A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unkno… Tailoring Management System No fix yet Fix from $1,9502024-08-06 CRITICAL 9.8 CVE-2024-7500 A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_… Airline Reservation System No fix yet Fix from $2,3002024-08-06 HIGH 8.8 CVE-2024-6315 The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' func… Mitigation only Fix from $1,9502024-08-06