Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2024-37762
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
Machform
21+
MEDIUM 6.5
CVE-2024-36987
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged …
Cloud
9.0.10 / 9.1.5+
HIGH 7.2
CVE-2024-3123
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator priv…
Mitigation only
CRITICAL 9.8
CVE-2024-6127EPSS 10%
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker ca…
Mitigation only
CRITICAL 9.8
CVE-2024-6373
A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vulnerability affects unknown c…
Online Food Ordering System
No fix yet
HIGH 8.8
CVE-2024-6054
The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachme…
Auto Featured Image
after 1.2
CRITICAL 9.8
CVE-2024-35527
An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execut…
Mitigation only
HIGH 8.8
CVE-2024-5008EPSS 17%
In WhatsUp Gold versions released before 2023.1.3,
an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using…
Whatsup Gold
23.1.3+
CRITICAL 9.8
CVE-2024-4197
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component…
Ip Office
11.1.3.1+
CRITICAL 9.8
CVE-2024-37228
Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a…
Instawp Connect
0.1.0.39+
HIGH 8.8
CVE-2024-24551
A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulner…
Bludit
after 3.15.0
HIGH 8.1
CVE-2024-24550
A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File…
Bludit
after 3.15.0
CRITICAL 9.8
CVE-2024-6280
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the…
Simple Online Bidding System
No fix yet
HIGH 7.2
CVE-2024-35767
Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This issue affects Squeeze: from n/a…
Squeeze
1.4.1+
CRITICAL 9.8
CVE-2023-45197
The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. …
Adminerevo
4.8.3+
HIGH 7.4
CVE-2024-28147
An authenticated user can upload arbitrary files in the upload
function for collection preview images. An attacker may upload an HTML
file that inc…
No fix yet
CRITICAL 10.0
CVE-2024-34990
In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload …
Mitigation only
CRITICAL 9.8
CVE-2024-33836
In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In v…
Mitigation only
HIGH 8.8
CVE-2024-22263EPSS 18%
Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the abili…
Mitigation only
HIGH 8.8
CVE-2024-5853
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s…
Sirv
7.2.7+
HIGH 8.8
CVE-2024-6132
The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'pexels_fsp_ima…
Mitigation only
CRITICAL 9.8
CVE-2024-3229
The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_Impo…
Salon Booking System
10.3+
HIGH 8.8
CVE-2024-2381
The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the…
Aliexpress Dropshipping With Alinext
3.3.6+
CRITICAL 9.8
CVE-2024-6116
A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue …
Simple Online Hotel Reservation System
No fix yet
CRITICAL 9.8
CVE-2024-6115
A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this vulnerability is an unk…
Simple Online Hotel Reservation System
No fix yet
CRITICAL 9.8
CVE-2024-6114
A vulnerability classified as critical has been found in itsourcecode Monbela Tourist Inn Online Reservation System up to 1.0. Affected is an unknown…
Monbela Tourist Inn Online Reservation System
No fix yet
CRITICAL 9.8
CVE-2024-6110
A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this …
Magbanua Beach Resort Online Reservation System
No fix yet
CRITICAL 9.8
CVE-2024-6084
A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vuln…
Pool Of Bethesda Online Reservation System
No fix yet
CRITICAL 9.8
CVE-2024-6083
A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp…
Phpvibe
Mitigation only
CRITICAL 9.8
CVE-2024-34833
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated …
Payroll Management System
No fix yet