Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2024-3912 Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to … Mitigation only Fix from $2,3002024-06-14 HIGH 7.2 CVE-2024-31161 The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this… Download Master 3.1.0.114+ Fix from $1,9502024-06-14 CRITICAL 9.8 CVE-2024-31777 File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoi… Openeclass after 3.15 Fix from $2,3002024-06-13 HIGH 8.8 CVE-2024-36396 Verint - CWE-434: Unrestricted Upload of File with Dangerous Type Workforce Optimization 15.2.1030+ Fix from $1,9502024-06-13 HIGH 7.2 CVE-2024-34110 Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerabil… Commerce after 1.4.0 Fix from $1,9502024-06-13 CRITICAL 9.8 CVE-2024-1659 Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authe… Megabip after 5.10 Fix from $2,3002024-06-12 MEDIUM 6.5 CVE-2024-34683 An authenticated attacker can upload malicious file to SAP Document Builder service. When the victim accesses this file, the attacker is allowed to a… Document Builder Patch available Fix from $1,6002024-06-11 HIGH 8.8 CVE-2024-36415 SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in upload… Suitecrm 7.14.4 / 8.6.1+ Fix from $1,9502024-06-10 CRITICAL 9.8 CVE-2024-35746 Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects BuddyPres… Buddypress Cover after 2.1.4.2 Fix from $2,3002024-06-10 CRITICAL 9.8 CVE-2023-45188 IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper vali… Engineering Lifecycle Optimization Publishing Mitigation only Fix from $2,3002024-06-09 CRITICAL 9.8 CVE-2024-5745 A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affected is an unknown function of t… Bakery Online Ordering System No fix yet Fix from $2,3002024-06-07 HIGH 8.8 CVE-2024-5734 A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknown function of the file /membe… Online Discussion Forum No fix yet Fix from $1,9502024-06-07 HIGH 7.2 CVE-2024-36774 An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file. Monstra No fix yet Fix from $1,9502024-06-06 MEDIUM 6.1 CVE-2024-5278 gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/… Chuanhuchatgpt 20240919+ Fix from $1,6002024-06-06 CRITICAL 9.8 CVE-2024-37273 An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploadin… Jan No fix yet Fix from $2,3002024-06-04 CRITICAL 9.8 CVE-2024-36858 An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading… Jan No fix yet Fix from $2,3002024-06-04 HIGH 7.2 CVE-2023-33930 Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates… Unlimited Elements For Elementor 1.5.67+ Fix from $1,9502024-06-04 MEDIUM 5.4 CVE-2024-0757 The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be i… Insert Or Embed Articulate Content after 4.3000000023 Fix from $1,6002024-06-04 CRITICAL 9.8 CVE-2024-29974EPSS 23% ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before… Nas326 Firmware 5.21+ Fix from $2,3002024-06-04 HIGH 7.2 CVE-2024-29848EPSS 64% An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbit… Avalanche 6.4.3.602+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-5518 A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_pr… Online Discussion Forum No fix yet Fix from $1,9502024-05-30 CRITICAL 9.1 CVE-2024-3412 The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… Mitigation only Fix from $2,3002024-05-29 HIGH 7.5 CVE-2024-22641 TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. Tcpdf after 6.7.4 Fix from $1,9502024-05-28 CRITICAL 9.8 CVE-2024-35510 An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading … Dedecms No fix yet Fix from $2,3002024-05-28 HIGH 8.1 CVE-2023-46694 Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due … Mitigation only Fix from $1,9502024-05-28 HIGH 8.8 CVE-2022-45171 An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShar… Vdesk after 018 Fix from $1,9502024-05-28 CRITICAL 9.8 CVE-2024-5377 A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affects an unknown part of the fi… Vehicle Management System No fix yet Fix from $2,3002024-05-26 MEDIUM 5.5 CVE-2024-35593 An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arbitrary code via uploading a c… Mitigation only Fix from $1,6002024-05-24 MEDIUM 5.4 CVE-2024-1332 The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up t… Custom Fonts 2.1.5+ Fix from $1,6002024-05-24 HIGH 8.8 CVE-2024-5247EPSS 27% NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remot… Prosafe Network Management System 1.7.0.37+ Fix from $1,9502024-05-23