Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.9 CVE-2024-37762 MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution. Machform 21+ Fix from $2,3002024-07-01 MEDIUM 6.5 CVE-2024-36987 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged … Cloud 9.0.10 / 9.1.5+ Fix from $1,6002024-07-01 HIGH 7.2 CVE-2024-3123 CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator priv… Mitigation only Fix from $1,9502024-07-01 CRITICAL 9.8 CVE-2024-6127EPSS 10% BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker ca… Mitigation only Fix from $2,3002024-06-27 CRITICAL 9.8 CVE-2024-6373 A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vulnerability affects unknown c… Online Food Ordering System No fix yet Fix from $2,3002024-06-27 HIGH 8.8 CVE-2024-6054 The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachme… Auto Featured Image after 1.2 Fix from $1,9502024-06-27 CRITICAL 9.8 CVE-2024-35527 An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execut… Mitigation only Fix from $2,3002024-06-25 HIGH 8.8 CVE-2024-5008EPSS 17% In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using… Whatsup Gold 23.1.3+ Fix from $1,9502024-06-25 CRITICAL 9.8 CVE-2024-4197 An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component… Ip Office 11.1.3.1+ Fix from $2,3002024-06-25 CRITICAL 9.8 CVE-2024-37228 Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a… Instawp Connect 0.1.0.39+ Fix from $2,3002024-06-24 HIGH 8.8 CVE-2024-24551 A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulner… Bludit after 3.15.0 Fix from $1,9502024-06-24 HIGH 8.1 CVE-2024-24550 A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File… Bludit after 3.15.0 Fix from $1,9502024-06-24 CRITICAL 9.8 CVE-2024-6280 A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the… Simple Online Bidding System No fix yet Fix from $2,3002024-06-24 HIGH 7.2 CVE-2024-35767 Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a… Squeeze 1.4.1+ Fix from $1,9502024-06-21 CRITICAL 9.8 CVE-2023-45197 The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. … Adminerevo 4.8.3+ Fix from $2,3002024-06-21 HIGH 7.4 CVE-2024-28147 An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that inc… No fix yet Fix from $1,9502024-06-20 CRITICAL 10.0 CVE-2024-34990 In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload … Mitigation only Fix from $2,3002024-06-19 CRITICAL 9.8 CVE-2024-33836 In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In v… Mitigation only Fix from $2,3002024-06-19 HIGH 8.8 CVE-2024-22263EPSS 18% Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the abili… Mitigation only Fix from $1,9502024-06-19 HIGH 8.8 CVE-2024-5853 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s… Sirv 7.2.7+ Fix from $1,9502024-06-19 HIGH 8.8 CVE-2024-6132 The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'pexels_fsp_ima… Mitigation only Fix from $1,9502024-06-19 CRITICAL 9.8 CVE-2024-3229 The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_Impo… Salon Booking System 10.3+ Fix from $2,3002024-06-19 HIGH 8.8 CVE-2024-2381 The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… Aliexpress Dropshipping With Alinext 3.3.6+ Fix from $1,9502024-06-19 CRITICAL 9.8 CVE-2024-6116 A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue … Simple Online Hotel Reservation System No fix yet Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-6115 A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unk… Simple Online Hotel Reservation System No fix yet Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-6114 A vulnerability classified as critical has been found in itsourcecode Monbela Tourist Inn Online Reservation System up to 1.0. Affected is an unknown… Monbela Tourist Inn Online Reservation System No fix yet Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-6110 A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this … Magbanua Beach Resort Online Reservation System No fix yet Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-6084 A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vuln… Pool Of Bethesda Online Reservation System No fix yet Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-6083 A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp… Phpvibe Mitigation only Fix from $2,3002024-06-18 CRITICAL 9.8 CVE-2024-34833 Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated … Payroll Management System No fix yet Fix from $2,3002024-06-17