Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2023-6887 A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img… Forestblog after 2022-06-30 Fix from $2,3002023-12-17 CRITICAL 9.8 CVE-2023-6850 A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the fi… Kodexplorer 4.52.01+ Fix from $2,3002023-12-16 HIGH 8.8 CVE-2023-48394 Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote at… Webitr Attendance System Mitigation only Fix from $1,9502023-12-15 HIGH 7.2 CVE-2023-6826 The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in ve… E2pdf after 1.20.25 Fix from $1,9502023-12-15 HIGH 8.8 CVE-2023-6827 The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFon… Essential Real Estate after 4.3.5 Fix from $1,9502023-12-15 CRITICAL 9.8 CVE-2023-48376 SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unau… Cws Collaborative Development Platform Mitigation only Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-48371 ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit th… Omicard Edm Mitigation only Fix from $2,3002023-12-15 HIGH 8.8 CVE-2023-50564EPSS 29% An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via … Pluck No fix yet Fix from $1,9502023-12-14 CRITICAL 9.8 CVE-2023-6723 An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfi… Repox Mitigation only Fix from $2,3002023-12-13 HIGH 8.8 CVE-2023-4122 Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authe… Student Information System No fix yet Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-6576 A vulnerability was found in Byzoro S210 up to 20231123. It has been declared as critical. This vulnerability affects unknown code of the file /Tool/… Smart S210 Firmware after 2023-11-21 Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-6574 A vulnerability was found in Byzoro Smart S20 up to 20231120 and classified as critical. Affected by this issue is some unknown functionality of the … Smart S20 Firmware after 2023-11-20 Fix from $1,9502023-12-07 HIGH 7.8 CVE-2023-39538 AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A s… Aptio V Mitigation only Fix from $1,9502023-12-06 HIGH 7.8 CVE-2023-39539 AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A s… Aptio V Mitigation only Fix from $1,9502023-12-06 CRITICAL 9.8 CVE-2023-48930 xinhu xinhuoa 2.2.1 contains a File upload vulnerability. Xinhu No fix yet Fix from $2,3002023-12-06 MEDIUM 5.4 CVE-2023-40460 The ACEManager component of ALEOS 4.16 and earlier does not validate uploaded file names and types, which could potentially allow an authentica… Aleos after 4.16.0 Fix from $1,6002023-12-04 HIGH 8.8 CVE-2023-5953 The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJ… Welcart E Commerce 2.9.5+ Fix from $1,9502023-12-04 HIGH 8.8 CVE-2023-48965 An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malici… Thinkadmin No fix yet Fix from $1,9502023-12-04 HIGH 8.8 CVE-2023-48966 An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a… Thinkadmin No fix yet Fix from $1,9502023-12-04 CRITICAL 9.8 CVE-2023-5636 Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. This issue affects Education … Arslansoft Education Portal 1.1+ Fix from $2,3002023-12-01 HIGH 7.5 CVE-2023-5637 Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Read Sensitive Strings Within an Executable. Thi… Arslansoft Education Portal 1.1+ Fix from $1,9502023-12-01 HIGH 7.2 CVE-2023-6449 The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function a… Contact Form 7 5.8.4+ Fix from $1,9502023-12-01 HIGH 7.2 CVE-2023-5966 An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, … Espocrm after 7.5.2 Fix from $1,9502023-11-30 HIGH 7.2 CVE-2023-5965 An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could le… Espocrm after 7.5.2 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-49052 File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function i… Microweber Patch available Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-4226 Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remo… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4224 Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain r… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4225 Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain … Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4223 Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain … Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 MEDIUM 6.1 CVE-2023-4220EPSS 76% Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows… Chamilo Lms after 1.11.24 Fix from $1,6002023-11-28