Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-6887
A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img…
Forestblog
after 2022-06-30
CRITICAL 9.8
CVE-2023-6850
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the fi…
Kodexplorer
4.52.01+
HIGH 8.8
CVE-2023-48394
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote at…
Webitr Attendance System
Mitigation only
HIGH 7.2
CVE-2023-6826
The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in ve…
E2pdf
after 1.20.25
HIGH 8.8
CVE-2023-6827
The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFon…
Essential Real Estate
after 4.3.5
CRITICAL 9.8
CVE-2023-48376
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unau…
Cws Collaborative Development Platform
Mitigation only
CRITICAL 9.8
CVE-2023-48371
ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit th…
Omicard Edm
Mitigation only
HIGH 8.8
CVE-2023-50564EPSS 29%
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via …
Pluck
No fix yet
CRITICAL 9.8
CVE-2023-6723
An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfi…
Repox
Mitigation only
HIGH 8.8
CVE-2023-4122
Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authe…
Student Information System
No fix yet
HIGH 8.8
CVE-2023-6576
A vulnerability was found in Byzoro S210 up to 20231123. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/…
Smart S210 Firmware
after 2023-11-21
HIGH 8.8
CVE-2023-6574
A vulnerability was found in Byzoro Smart S20 up to 20231120 and classified as critical. Affected by this issue is some unknown functionality of the …
Smart S20 Firmware
after 2023-11-20
HIGH 7.8
CVE-2023-39538
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A s…
Aptio V
Mitigation only
HIGH 7.8
CVE-2023-39539
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A s…
Aptio V
Mitigation only
CRITICAL 9.8
CVE-2023-48930
xinhu xinhuoa 2.2.1 contains a File upload vulnerability.
Xinhu
No fix yet
MEDIUM 5.4
CVE-2023-40460
The ACEManager
component of ALEOS 4.16 and earlier does not
validate uploaded
file names and types, which could potentially allow
an authentica…
Aleos
after 4.16.0
HIGH 8.8
CVE-2023-5953
The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJ…
Welcart E Commerce
2.9.5+
HIGH 8.8
CVE-2023-48965
An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malici…
Thinkadmin
No fix yet
HIGH 8.8
CVE-2023-48966
An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a…
Thinkadmin
No fix yet
CRITICAL 9.8
CVE-2023-5636
Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection.
This issue affects Education …
Arslansoft Education Portal
1.1+
HIGH 7.5
CVE-2023-5637
Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Read Sensitive Strings Within an Executable.
Thi…
Arslansoft Education Portal
1.1+
HIGH 7.2
CVE-2023-6449
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function a…
Contact Form 7
5.8.4+
HIGH 7.2
CVE-2023-5966
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, …
Espocrm
after 7.5.2
HIGH 7.2
CVE-2023-5965
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could le…
Espocrm
after 7.5.2
HIGH 8.8
CVE-2023-49052
File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i…
Microweber
Patch available
HIGH 8.8
CVE-2023-4226
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remo…
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4224
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain r…
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4225
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4223
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …
Chamilo Lms
after 1.11.24
MEDIUM 6.1
CVE-2023-4220EPSS 76%
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows…
Chamilo Lms
after 1.11.24