Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.3 CVE-2024-3804 A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processin… Mitigation only Fix from $1,6002024-04-15 MEDIUM 6.3 CVE-2024-3803 A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Publi… Mitigation only Fix from $1,6002024-04-15 HIGH 7.2 CVE-2024-3778 The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privileg… Qbibot Mitigation only Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-3736 A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function uplo… Nginxwebui 4.2.4+ Fix from $1,9502024-04-13 HIGH 8.8 CVE-2024-3705 Unrestricted file upload vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to send a POST request t… Opengnsys Mitigation only Fix from $1,9502024-04-12 CRITICAL 9.8 CVE-2023-51409EPSS 63% Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:… Ai Engine 1.9.99+ Fix from $2,3002024-04-12 MEDIUM 5.4 CVE-2024-3344 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV… Otter Blocks 2.6.9+ Fix from $1,6002024-04-11 CRITICAL 9.6 CVE-2024-31214EPSS 18% Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload… Traccar after 5.12 Fix from $2,3002024-04-10 CRITICAL 9.8 CVE-2024-2221 qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint… Qdrant Patch available Fix from $2,3002024-04-10 HIGH 8.5 CVE-2024-24809EPSS 54% Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous … Patch available Fix from $1,9502024-04-10 MEDIUM 6.4 CVE-2024-2334 The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up … Mitigation only Fix from $1,6002024-04-09 HIGH 8.8 CVE-2024-2125 The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… Envialosimple 2.4+ Fix from $1,9502024-04-09 MEDIUM 6.5 CVE-2024-31454 PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which is desig… Patch available Fix from $1,6002024-04-09 MEDIUM 6.5 CVE-2024-31453 PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which allows u… Patch available Fix from $1,6002024-04-09 HIGH 7.2 CVE-2024-3436 A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code o… Prison Management System No fix yet Fix from $1,9502024-04-08 HIGH 7.2 CVE-2024-3437 A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing o… Prison Management System No fix yet Fix from $1,9502024-04-08 CRITICAL 9.1 CVE-2024-31345 Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2. Mitigation only Fix from $2,3002024-04-07 CRITICAL 9.9 CVE-2024-31286 Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album … Mitigation only Fix from $2,3002024-04-07 HIGH 7.2 CVE-2024-31292 Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: f… Mitigation only Fix from $1,9502024-04-07 HIGH 8.8 CVE-2024-31280 Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a throu… Church Admin 4.1.6+ Fix from $1,9502024-04-07 HIGH 8.8 CVE-2024-3369 A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionali… Car Rental No fix yet Fix from $1,9502024-04-06 HIGH 8.8 CVE-2024-31210 WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an … WordPress 4.1.40 / 4.2.37+ Fix from $1,9502024-04-04 HIGH 8.8 CVE-2024-29387 projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php. Projeqtor after 11.2.0 Fix from $1,9502024-04-04 MEDIUM 6.5 CVE-2024-28520 File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to… Mitigation only Fix from $1,6002024-04-04 HIGH 7.2 CVE-2024-3022 The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in the 'bookingpress_process_up… Bookingpress after 1.0.87 Fix from $1,9502024-04-04 HIGH 7.2 CVE-2024-27951 Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Se… Multiple Page Generator 3.4.1+ Fix from $1,9502024-04-03 CRITICAL 9.8 CVE-2024-31012 An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via… Semcms No fix yet Fix from $2,3002024-04-03 HIGH 8.8 CVE-2024-29514 File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file. Leptoncms No fix yet Fix from $1,9502024-04-02 MEDIUM 6.3 CVE-2024-3129 A vulnerability was found in SourceCodester Image Accordion Gallery App 1.0. It has been classified as critical. This affects an unknown part of the … Image Accordion Gallery App No fix yet Fix from $1,6002024-04-01 HIGH 7.5 CVE-2024-30533 Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a b… Mitigation only Fix from $1,9502024-03-31