Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2023-6219 The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'bookingpress_process_upload… Bookingpress after 1.0.76 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-29770 In Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension filtering. Sentrifugo No fix yet Fix from $1,9502023-11-28 CRITICAL 9.8 CVE-2023-5604 The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configu… Asgaros Forum 2.7.1+ Fix from $2,3002023-11-27 CRITICAL 9.8 CVE-2023-41998EPSS 15% Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows … Udp 9.2+ Fix from $2,3002023-11-27 HIGH 8.8 CVE-2023-6308 A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by th… Video Surveillance Management System No fix yet Fix from $1,9502023-11-27 CRITICAL 9.8 CVE-2023-6274 A vulnerability was found in Byzoro Smart S80 up to 20231108. It has been declared as critical. Affected by this vulnerability is an unknown function… Smart S80 Firmware after 2023-11-08 Fix from $2,3002023-11-24 HIGH 8.8 CVE-2023-41812 Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. … Pandora Fms 774+ Fix from $1,9502023-11-23 HIGH 8.8 CVE-2023-41788 Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. … Pandora Fms 774+ Fix from $1,9502023-11-23 CRITICAL 9.8 CVE-2023-5822 The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type va… Drag And Drop Multiple File Upload Contact Form 7 after 1.3.7.3 Fix from $2,3002023-11-22 HIGH 8.8 CVE-2023-6187EPSS 52% The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalex… Paid Memberships Pro after 2.12.3 Fix from $1,9502023-11-18 HIGH 8.8 CVE-2023-39548 CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSaf… Expresscluster X Patch available Fix from $1,9502023-11-17 CRITICAL 9.8 CVE-2023-48031 OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restr… Opensupports No fix yet Fix from $2,3002023-11-17 HIGH 8.8 CVE-2023-48217 Statamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look… Statamic 3.4.14 / 4.34.0+ Fix from $1,9502023-11-14 MEDIUM 5.4 CVE-2023-6127 Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. Suitecrm 7.12.14+ Fix from $1,6002023-11-14 HIGH 8.8 CVE-2023-47621 Guest Entries is a php library which allows users to create, update & delete entries from the front-end of a site. In affected versions the file uplo… Guest Entries 3.1.3+ Fix from $1,9502023-11-13 CRITICAL 9.8 CVE-2023-6102 A vulnerability, which was classified as problematic, was found in Maiwei Safety Production Control Platform 4.1. Affected is an unknown function of … Maiwei Safety Production Control Platform Mitigation only Fix from $2,3002023-11-13 CRITICAL 9.8 CVE-2023-47129 Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload fi… Statamic 3.4.13 / 4.33.0+ Fix from $2,3002023-11-10 HIGH 8.8 CVE-2023-42659 In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has … Ws Ftp Server 8.7.6 / 8.8.4+ Fix from $1,9502023-11-07 HIGH 8.8 CVE-2023-33480 RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create ad… Remote Clinic No fix yet Fix from $1,9502023-11-07 CRITICAL 9.8 CVE-2023-5601 The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated use… Woocommerce Ninja Forms Product Add Ons 1.7.1+ Fix from $2,3002023-11-06 HIGH 7.8 CVE-2023-41725 Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability Avalanche 6.4.1.236+ Fix from $1,9502023-11-03 HIGH 8.8 CVE-2023-41357 Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during fi… Vitals Enterprise Social Platform after 6.1 Fix from $1,9502023-11-03 HIGH 7.2 CVE-2023-5919 A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionali… Company Website Cms No fix yet Fix from $1,9502023-11-02 CRITICAL 9.8 CVE-2023-42802 GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation … Glpi 10.0.10+ Fix from $2,3002023-11-02 HIGH 7.2 CVE-2023-5860 The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all … Icons Font Loader 1.1.3+ Fix from $1,9502023-11-02 HIGH 8.8 CVE-2023-46428 An arbitrary file upload vulnerability in HadSky v7.12.10 allows attackers to execute arbitrary code via a crafted file. Hadsky No fix yet Fix from $1,9502023-11-01 HIGH 7.2 CVE-2023-20196 Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vuln… Identity Services Engine Mitigation only Fix from $1,9502023-11-01 HIGH 7.2 CVE-2023-20195 Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vuln… Identity Services Engine Mitigation only Fix from $1,9502023-11-01 HIGH 8.0 CVE-2023-1720 Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's bro… Bitrix24 No fix yet Fix from $1,9502023-11-01 HIGH 8.8 CVE-2023-1713 Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote… Bitrix24 No fix yet Fix from $1,9502023-11-01