Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2024-40394 Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax… Simple Library Management System No fix yet Fix from $2,3002024-07-16 CRITICAL 9.8 CVE-2024-40425 File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute ar… Sparkshop 1.1.7+ Fix from $2,3002024-07-16 MEDIUM 5.3 CVE-2024-40555 Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability. Tmall Demo No fix yet Fix from $1,6002024-07-15 HIGH 8.8 CVE-2024-5630 The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site,… Insert Or Embed Articulate Content 4.3000000024+ Fix from $1,9502024-07-15 MEDIUM 6.3 CVE-2024-6730 A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown proc… Mitigation only Fix from $1,6002024-07-14 HIGH 8.8 CVE-2024-5080 The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP … Wp Emember 10.6.6+ Fix from $1,9502024-07-13 CRITICAL 9.1 CVE-2024-5450 The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload … Bug Library 2.1.1+ Fix from $2,3002024-07-13 HIGH 8.8 CVE-2024-40545 An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary c… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40546 An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code … Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40548 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40549 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40550 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40551 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary … Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 CRITICAL 9.1 CVE-2024-38736 Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realty… Mitigation only Fix from $2,3002024-07-12 CRITICAL 9.1 CVE-2024-38734 Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.… Mitigation only Fix from $2,3002024-07-12 HIGH 8.8 CVE-2023-7061 The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This m… File Manager Advanced Shortcode after 2.5.3 Fix from $1,9502024-07-10 HIGH 8.8 CVE-2024-39865 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application allows users to upload encryp… Sinema Remote Connect Server 3.2+ Fix from $1,9502024-07-09 CRITICAL 9.9 CVE-2024-37424 Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affe… Mitigation only Fix from $2,3002024-07-09 CRITICAL 9.9 CVE-2024-37418 Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a throu… Church Admin 4.4.7+ Fix from $2,3002024-07-09 CRITICAL 9.9 CVE-2024-37420 Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web Shell to a Web Server.This is… Mitigation only Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2024-6314 The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process_image_uploa… Mitigation only Fix from $2,3002024-07-09 HIGH 8.8 CVE-2024-6161 The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'get_cache_image' … Mitigation only Fix from $1,9502024-07-09 CRITICAL 9.8 CVE-2024-6313 The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowed file types in the 'upload' … Mitigation only Fix from $2,3002024-07-09 CRITICAL 9.8 CVE-2024-37555 Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This … Generate Pdf Using Contact Form 7 after 4.0.9 Fix from $2,3002024-07-09 HIGH 7.2 CVE-2024-6123 The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'iconUpload' function in all ver… Mitigation only Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-5441 The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image… Modern Events Calendar Lite 7.12.0+ Fix from $1,9502024-07-09 CRITICAL 9.8 CVE-2024-27903EPSS 9% OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in … Openvpn 2.5.10 / 2.6.10+ Fix from $2,3002024-07-08 HIGH 8.8 CVE-2024-6319 The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versio… Imgspider 2.3.11+ Fix from $1,9502024-07-04 HIGH 8.8 CVE-2024-6318 The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in a… Imgspider 2.3.11+ Fix from $1,9502024-07-04 CRITICAL 9.8 CVE-2024-6439 A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown … Home Owners Collection Management System No fix yet Fix from $2,3002024-07-02