Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2024-1819 A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the comp… Membership Management System No fix yet Fix from $1,9502024-02-23 CRITICAL 9.8 CVE-2024-25802 SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content. S Museum Mitigation only Fix from $2,3002024-02-22 CRITICAL 9.1 CVE-2024-22393 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack b… Answer 1.2.5+ Fix from $2,3002024-02-22 HIGH 7.2 CVE-2024-27283 A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload potentially malicious files to … Ediscovery Platform 10.2.5+ Fix from $1,9502024-02-22 MEDIUM 6.1 CVE-2024-25801 SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the conten… S Museum Mitigation only Fix from $1,6002024-02-22 HIGH 7.2 CVE-2023-52154 File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files. Pmb after 7.4.7 Fix from $1,9502024-02-21 CRITICAL 9.8 CVE-2024-25274 An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploa… Novel Plus Mitigation only Fix from $2,3002024-02-20 CRITICAL 9.8 CVE-2024-22824 An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component. Timo No fix yet Fix from $2,3002024-02-20 HIGH 8.8 CVE-2024-1644 Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI. Suitecrm No fix yet Fix from $1,9502024-02-20 HIGH 8.8 CVE-2024-25636 Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Str… Misskey 2024.2.0+ Fix from $1,9502024-02-19 HIGH 7.7 CVE-2024-25623 Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote… Mastodon 3.5.19 / 4.0.15+ Fix from $1,9502024-02-19 CRITICAL 9.8 CVE-2022-42443 An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploadi… Trusteer Android Sdk For Mobile 5.7+ Fix from $2,3002024-02-17 CRITICAL 9.8 CVE-2024-22426 Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potent… Recoverpoint For Virtual Machines Mitigation only Fix from $2,3002024-02-16 CRITICAL 9.8 CVE-2024-25414 An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip fil… Csz Cms No fix yet Fix from $2,3002024-02-16 HIGH 8.8 CVE-2024-23811 A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application allows users to upload arbitrary files via TFTP.… Sinec Nms 2.0+ Fix from $1,9502024-02-13 CRITICAL 9.8 CVE-2024-23759EPSS 48% Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/Add… Gambio No fix yet Fix from $2,3002024-02-12 HIGH 7.8 CVE-2024-23762 Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted … Gambio No fix yet Fix from $1,9502024-02-12 HIGH 8.8 CVE-2023-50386EPSS 84% Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co… Solr 8.11.3 / 9.4.1+ Fix from $1,9502024-02-09 CRITICAL 9.8 CVE-2024-25674 An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type. Misp 2.4.184+ Fix from $2,3002024-02-09 CRITICAL 9.8 CVE-2024-24393 File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request. Pichome No fix yet Fix from $2,3002024-02-08 HIGH 7.8 CVE-2023-25365 Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3 October No fix yet Fix from $1,9502024-02-08 HIGH 8.8 CVE-2023-40265 An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution v… Unify Openscape Xpressions Webassistant 7r1_fr5_hf42_p911+ Fix from $1,9502024-02-08 CRITICAL 9.8 CVE-2024-24202 An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows atta… Zentao No fix yet Fix from $2,3002024-02-08 CRITICAL 9.8 CVE-2024-24024 An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). A… Novel Plus after 4.2.0 Fix from $2,3002024-02-08 CRITICAL 9.8 CVE-2024-24025 An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attack… Novel Plus after 4.2.0 Fix from $2,3002024-02-08 CRITICAL 9.8 CVE-2024-24026 An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadI… Novel Plus after 4.2.0 Fix from $2,3002024-02-08 HIGH 8.8 CVE-2024-24350 File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filte… E Sic Livre after 2.0 Fix from $1,9502024-02-08 CRITICAL 9.8 CVE-2024-1268 A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_… Restaurant Pos System Mitigation only Fix from $2,3002024-02-07 CRITICAL 9.8 CVE-2024-1264 A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate… Jpshop after 1.5.02 Fix from $2,3002024-02-07 CRITICAL 9.8 CVE-2024-1262 A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the… Jpshop after 1.5.02 Fix from $2,3002024-02-06