Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2024-35079 An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted… Inxedu Mitigation only Fix from $2,3002024-05-23 CRITICAL 9.8 CVE-2024-35080 An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp f… Inxedu Mitigation only Fix from $2,3002024-05-23 CRITICAL 9.8 CVE-2024-35375 There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS Dedecms Mitigation only Fix from $2,3002024-05-23 CRITICAL 9.8 CVE-2024-35570 An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows attackers to execute arbitrar… Inxedu No fix yet Fix from $2,3002024-05-23 CRITICAL 9.8 CVE-2024-5084EPSS 51% The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fil… Hash Form 1.1.1+ Fix from $2,3002024-05-23 HIGH 8.8 CVE-2024-5145 A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue affects some unknown processin… Vehicle Management System No fix yet Fix from $1,9502024-05-20 HIGH 8.8 CVE-2024-5049 A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionali… E Commerce Site No fix yet Fix from $1,9502024-05-17 MEDIUM 6.3 CVE-2024-5050 A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=lo… Mitigation only Fix from $1,6002024-05-17 CRITICAL 9.8 CVE-2024-5047 A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an unknown function of the file /s… Student Management System No fix yet Fix from $2,3002024-05-17 CRITICAL 9.8 CVE-2024-34982 An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via upload… Lylme Spage No fix yet Fix from $2,3002024-05-17 HIGH 8.8 CVE-2024-5043 A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setti… Emlog No fix yet Fix from $1,9502024-05-17 CRITICAL 10.0 CVE-2024-32809 Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveD… Mitigation only Fix from $2,3002024-05-17 CRITICAL 9.8 CVE-2024-31351 Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – A… Copymatic 1.7+ Fix from $2,3002024-05-17 CRITICAL 9.8 CVE-2024-33556 Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8. Xstore Core 5.3.9+ Fix from $2,3002024-05-17 CRITICAL 9.1 CVE-2023-25444 Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Using Malicious F… Js Help Desk 2.7.8+ Fix from $2,3002024-05-17 CRITICAL 9.8 CVE-2024-4966 A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /impro… Schoolwebtech No fix yet Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4964 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000-40 V31R02B1413C and classified as critical. This vulnerability affe… Dar 7000 Firmware Mitigation only Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4963 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000-40 V31R02B1413C. This affects an unkn… Dar 7000 Firmware Mitigation only Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4962 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 V31R02B1413C. Affected by thi… Dar 7000 Firmware Mitigation only Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4961 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability i… Dar 7000 Firmware Mitigation only Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4960 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown func… Dar 7000 Firmware Mitigation only Fix from $2,3002024-05-16 HIGH 8.8 CVE-2024-4946 A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerabilit… Online Art Gallery Management System No fix yet Fix from $1,9502024-05-16 CRITICAL 9.8 CVE-2024-4945 A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown functio… Best Courier Management System No fix yet Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4927 A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an … Simple Online Bidding System No fix yet Fix from $2,3002024-05-16 HIGH 8.8 CVE-2024-4923 A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/… E Commerce Site No fix yet Fix from $1,9502024-05-16 CRITICAL 9.8 CVE-2024-4921 A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown fun… Employee And Visitor Gate Pass Logging System No fix yet Fix from $2,3002024-05-16 CRITICAL 9.8 CVE-2024-4920 A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processi… Online Discussion Forum Site No fix yet Fix from $2,3002024-05-16 MEDIUM 5.4 CVE-2024-34906 An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file. Dootask No fix yet Fix from $1,6002024-05-15 MEDIUM 5.4 CVE-2024-34909 An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file. Kykms after 1.0.1 Fix from $1,6002024-05-15 MEDIUM 5.4 CVE-2024-34913 An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF fil… R Pan Scaffolding after 5.0 Fix from $1,6002024-05-15