Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2023-39463 Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allo… Scada Data Gateway Mitigation only Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-38098EPSS 13% NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remot… Prosafe Network Management System 1.7.0.20+ Fix from $1,9502024-05-03 HIGH 8.8 CVE-2023-38095EPSS 66% NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allo… Prosafe Network Management System 1.7.0.20+ Fix from $1,9502024-05-03 HIGH 8.8 CVE-2024-4033 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_att… Mitigation only Fix from $1,9502024-05-02 CRITICAL 9.8 CVE-2024-2667EPSS 6% The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio… Instawp Connect 0.1.0.23+ Fix from $2,3002024-05-02 CRITICAL 9.8 CVE-2024-1567 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_… Royal Elementor Addons 1.3.95+ Fix from $2,3002024-05-02 HIGH 7.3 CVE-2024-4349 A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an … Pisay Online E Learning System No fix yet Fix from $1,9502024-04-30 HIGH 7.2 CVE-2024-28269 ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to uploa… Mitigation only Fix from $1,9502024-04-30 HIGH 8.0 CVE-2024-33438 File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. Cubecart 6.5.5+ Fix from $1,9502024-04-29 HIGH 8.8 CVE-2024-4306 Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious P… Hubbank Mitigation only Fix from $1,9502024-04-29 HIGH 7.2 CVE-2024-32880 pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template … Pyload after 0.5.0 Fix from $1,9502024-04-26 CRITICAL 9.8 CVE-2024-3962 The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the p… Product Addons \& Fields For Woocommerce 32.0.19+ Fix from $2,3002024-04-26 CRITICAL 10.0 CVE-2024-0916 Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3. Patch available Fix from $2,3002024-04-25 MEDIUM 6.3 CVE-2024-31610 File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to r… Simple School Management System No fix yet Fix from $1,6002024-04-25 CRITICAL 9.8 CVE-2024-31615 ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. Thinkcmf No fix yet Fix from $2,3002024-04-25 HIGH 8.8 CVE-2023-31090 Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates… Unlimited Elements For Elementor 1.5.61+ Fix from $1,9502024-04-24 CRITICAL 9.1 CVE-2024-32954 Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5. Mitigation only Fix from $2,3002024-04-24 CRITICAL 9.1 CVE-2024-32836 Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite … Mitigation only Fix from $2,3002024-04-24 MEDIUM 5.3 CVE-2024-28890 Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote at… Forminator 1.29.0+ Fix from $1,6002024-04-23 MEDIUM 6.5 CVE-2024-29368 An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renam… Mozilocms No fix yet Fix from $1,6002024-04-22 CRITICAL 9.8 CVE-2024-29661 A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload. Dedecms Mitigation only Fix from $2,3002024-04-22 HIGH 8.8 CVE-2024-23534 An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitra… Avalanche 6.4.3.528+ Fix from $1,9502024-04-19 CRITICAL 9.8 CVE-2024-3948 A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by this issue is some unknown func… Library System No fix yet Fix from $2,3002024-04-18 CRITICAL 9.8 CVE-2024-32161 jizhiCMS 2.5 suffers from a File upload vulnerability. Jizhicms Mitigation only Fix from $2,3002024-04-17 CRITICAL 9.9 CVE-2024-32514 Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll… Wp Poll Maker 3.5+ Fix from $2,3002024-04-17 HIGH 8.8 CVE-2024-31680 File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitr… Mitigation only Fix from $1,9502024-04-17 HIGH 8.1 CVE-2024-32256 Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When upda… Tourism Management System No fix yet Fix from $1,9502024-04-16 HIGH 8.8 CVE-2024-32254 Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When cre… Tourism Management System No fix yet Fix from $1,9502024-04-16 CRITICAL 9.8 CVE-2024-3863 The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other oper… Firefox 115.10 / 115.10.0+ Fix from $2,3002024-04-16 HIGH 7.2 CVE-2020-22539 An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a craf… Codoforum No fix yet Fix from $1,9502024-04-15