Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.3 CVE-2024-4904 A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This issue affects some unknown pro… Mitigation only Fix from $1,6002024-05-15 CRITICAL 9.8 CVE-2024-3488 File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a f… Imanager 3.2.6+ Fix from $2,3002024-05-15 CRITICAL 9.8 CVE-2024-3483 Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserializat… Imanager after 3.2.6 Fix from $2,3002024-05-15 CRITICAL 9.0 CVE-2024-32002EPSS 29% Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be c… Git 2.39.4 / 2.40.2+ Fix from $2,3002024-05-14 CRITICAL 9.6 CVE-2024-33006 An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise … Mitigation only Fix from $2,3002024-05-14 HIGH 7.2 CVE-2024-27945 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged u… Ruggedcom Crossbow 5.5+ Fix from $1,9502024-05-14 HIGH 7.2 CVE-2024-27944 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware file… Ruggedcom Crossbow 5.5+ Fix from $1,9502024-05-14 HIGH 7.2 CVE-2024-27943 A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files… Ruggedcom Crossbow 5.5+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-4825 A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post reque… Cockpit Mitigation only Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-4820 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is… Online Computer And Laptop Store No fix yet Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-4809 A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability … Open Source Clinic Management System No fix yet Fix from $2,3002024-05-14 HIGH 7.2 CVE-2024-4681 A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the fi… Legal Case Management System No fix yet Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-4560 The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_c… Mitigation only Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-4397 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_p… Learnpress 4.2.6.6+ Fix from $1,9502024-05-14 CRITICAL 10.0 CVE-2024-34555 Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3. Mitigation only Fix from $2,3002024-05-14 HIGH 7.2 CVE-2024-34440 Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:… Ai Engine 2.2.70+ Fix from $1,9502024-05-14 CRITICAL 9.1 CVE-2024-34416 Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1. Mitigation only Fix from $2,3002024-05-14 CRITICAL 9.9 CVE-2024-34411 Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through… Mitigation only Fix from $2,3002024-05-14 CRITICAL 10.0 CVE-2024-32700 Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for W… Mitigation only Fix from $2,3002024-05-14 CRITICAL 10.0 CVE-2024-31377 Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album … Mitigation only Fix from $2,3002024-05-14 MEDIUM 5.4 CVE-2023-50717 NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html fi… Nocodb 0.202.10+ Fix from $1,6002024-05-14 MEDIUM 6.5 CVE-2023-47711 IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force… Security Guardium Mitigation only Fix from $1,6002024-05-14 HIGH 8.8 CVE-2021-35002 BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a… Track It\! Mitigation only Fix from $1,9502024-05-07 CRITICAL 9.8 CVE-2024-33120 Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerabili… Roothub Mitigation only Fix from $2,3002024-05-07 CRITICAL 9.8 CVE-2024-4345 The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process'… Mitigation only Fix from $2,3002024-05-07 MEDIUM 6.3 CVE-2024-33752 An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker… Emlog No fix yet Fix from $1,6002024-05-06 HIGH 8.8 CVE-2024-4500 A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code o… Prison Management System No fix yet Fix from $1,9502024-05-05 CRITICAL 9.8 CVE-2024-33786 An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploadi… Mitigation only Fix from $2,3002024-05-03 CRITICAL 9.8 CVE-2023-51590 Voltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers t… Viewpower Mitigation only Fix from $2,3002024-05-03 MEDIUM 6.5 CVE-2023-39462 Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary fi… Scada Data Gateway Mitigation only Fix from $1,6002024-05-03