Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.1 CVE-2023-52086 resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/fo… Php Backend For Resumable.js Patch available Fix from $1,9502023-12-26 HIGH 8.8 CVE-2023-7091 A vulnerability was found in Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /upload/uplo… Dreamer Cms No fix yet Fix from $1,9502023-12-24 CRITICAL 9.8 CVE-2023-51034 TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface. Ex1200l Firmware No fix yet Fix from $2,3002023-12-22 CRITICAL 9.8 CVE-2023-42017 IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By s… Planning Analytics Mitigation only Fix from $2,3002023-12-22 MEDIUM 5.4 CVE-2023-7054 A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing… Online Notes Sharing System No fix yet Fix from $1,6002023-12-22 MEDIUM 5.4 CVE-2023-7036 A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function upload of the file FileCollection… Automad after 1.10.9 Fix from $1,6002023-12-21 CRITICAL 9.8 CVE-2022-45377 Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue af… Drag And Drop Multiple File Upload For Woocommerce 1.0.9+ Fix from $2,3002023-12-21 MEDIUM 6.5 CVE-2023-7026 A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of th… Iptv Gateway after 20231208 Fix from $1,6002023-12-21 HIGH 8.8 CVE-2023-23970 Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a through 1.5. Corsa after 1.5 Fix from $1,9502023-12-20 CRITICAL 9.8 CVE-2023-25970 Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshippi… Zendrop 1.0.1+ Fix from $2,3002023-12-20 CRITICAL 9.8 CVE-2023-45603 Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.Th… User Submitted Posts after 20230902 Fix from $2,3002023-12-20 HIGH 8.8 CVE-2023-46149 Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. Ultra after 7.3.5 Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-47784 Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a thro… Slider Revolution after 6.6.15 Fix from $1,9502023-12-20 HIGH 7.2 CVE-2023-49814 Unrestricted Upload of File with Dangerous Type vulnerability in Symbiostock symbiostock.This issue affects Symbiostock: from n/a through 6.0.0. Symbiostock after 6.0.0 Fix from $1,9502023-12-20 MEDIUM 6.5 CVE-2023-31231 Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates… Unlimited Elements For Elementor 1.5.66+ Fix from $1,6002023-12-20 HIGH 8.8 CVE-2023-33318 Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40. Automatewoo after 4.9.40 Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-34007 Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. Download Monitor after 4.8.3 Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-34385 Unrestricted Upload of File with Dangerous Type vulnerability in Akshay Menariya Export Import Menus.This issue affects Export Import Menus: from n/a… Export Import Menus after 1.8.0 Fix from $1,9502023-12-20 HIGH 7.2 CVE-2023-40204 Unrestricted Upload of File with Dangerous Type vulnerability in Premio Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, F… Folders after 2.9.2 Fix from $1,9502023-12-20 HIGH 7.2 CVE-2023-28170 Unrestricted Upload of File with Dangerous Type vulnerability in Themely Theme Demo Import.This issue affects Theme Demo Import: from n/a through 1.1… Theme Demo Import after 1.1.1 Fix from $1,9502023-12-20 HIGH 7.2 CVE-2023-29102 Unrestricted Upload of File with Dangerous Type vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Imp… Olive One Click Demo Import after 1.1.1 Fix from $1,9502023-12-20 CRITICAL 9.8 CVE-2023-29384 Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects Word… Jobwp after 2.0 Fix from $2,3002023-12-20 HIGH 8.8 CVE-2023-31215 Unrestricted Upload of File with Dangerous Type vulnerability in AmaderCode Lab Dropshipping & Affiliation with Amazon.This issue affects Dropshippin… Dropshipping \& Affiliation With Amazon after 2.1.2 Fix from $1,9502023-12-20 HIGH 7.5 CVE-2023-6562 JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server … Kakadu Sdk after 8.4 Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-6976 This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process. Mlflow 2.9.2+ Fix from $1,9502023-12-20 HIGH 8.8 CVE-2023-47706 IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. Security Guardium Key Lifecycle Manager 4.2.0.2+ Fix from $1,9502023-12-20 CRITICAL 9.8 CVE-2023-46263EPSS 82% An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… Avalanche 6.4.2+ Fix from $2,3002023-12-19 CRITICAL 9.8 CVE-2023-46264EPSS 90% An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… Avalanche 6.4.2+ Fix from $2,3002023-12-19 HIGH 8.8 CVE-2023-4311 The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode. Vrm360 after 1.2.1 Fix from $1,9502023-12-18 CRITICAL 9.8 CVE-2023-6902 A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the f… Stupid Simple Cms after 1.2.4 Fix from $2,3002023-12-17