Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2023-40050 Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with malicious… Automate after 4.10.29 Fix from $1,9502023-10-31 CRITICAL 9.8 CVE-2023-5360EPSS 82% The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated … Royal Elementor Addons 1.3.79+ Fix from $2,3002023-10-31 HIGH 8.8 CVE-2023-42803 BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the i… Bigbluebutton after 2.5.18 Fix from $1,9502023-10-30 HIGH 8.8 CVE-2023-5829 A vulnerability was found in code-projects Admission Management System 1.0. It has been rated as critical. Affected by this issue is some unknown fun… Admission Management System No fix yet Fix from $1,9502023-10-27 HIGH 8.8 CVE-2023-46815 An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes… Sugarcrm 12.0.4+ Fix from $1,9502023-10-27 HIGH 8.8 CVE-2023-5812 A vulnerability has been found in flusity CMS and classified as critical. Affected by this vulnerability is the function handleFileUpload of the file… Flusity after 2.304 Fix from $1,9502023-10-27 HIGH 8.8 CVE-2023-5796 A vulnerability was found in CodeAstro POS System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the fil… Pos System No fix yet Fix from $1,9502023-10-26 HIGH 8.8 CVE-2023-5795 A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality o… Pos System No fix yet Fix from $1,9502023-10-26 CRITICAL 9.8 CVE-2023-5790 A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality o… File Manager App No fix yet Fix from $2,3002023-10-26 CRITICAL 9.8 CVE-2023-45554 File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, j… Zzzcms No fix yet Fix from $2,3002023-10-25 HIGH 7.8 CVE-2023-45555 File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php… Zzzcms No fix yet Fix from $1,9502023-10-25 HIGH 8.8 CVE-2023-26578 Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root su… Idweb Mitigation only Fix from $1,9502023-10-25 HIGH 7.3 CVE-2023-5524 Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote … Web Companion 23.8 / 23.10+ Fix from $1,9502023-10-20 CRITICAL 9.8 CVE-2020-36706 The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/re… Simple\ 6.6.1+ Fix from $2,3002023-10-20 CRITICAL 9.8 CVE-2023-45384 KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout,… Supercheckout 6.0.7+ Fix from $2,3002023-10-19 HIGH 8.8 CVE-2023-37502 HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server … Hcl Compass 2.2.3+ Fix from $1,9502023-10-18 HIGH 7.2 CVE-2023-46004 Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function. Best Courier Management System No fix yet Fix from $1,9502023-10-18 HIGH 8.8 CVE-2023-41631 eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function. Esst Monitoring after 2.147.1 Fix from $1,9502023-10-17 CRITICAL 9.8 CVE-2023-45952 An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading … Lylme Spage No fix yet Fix from $2,3002023-10-17 HIGH 7.8 CVE-2023-44824 An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php componen… Expense Management System No fix yet Fix from $1,9502023-10-17 HIGH 8.8 CVE-2023-34207 Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remo… Mailhunter Ultimate after 2023 Fix from $1,9502023-10-17 HIGH 8.8 CVE-2022-22375 IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a s… Security Verify Privilege On Premises 11.5+ Fix from $1,9502023-10-17 CRITICAL 9.8 CVE-2011-10004 A vulnerability was found in reciply Plugin up to 1.1.7 on WordPress. It has been rated as critical. This issue affects some unknown processing of th… Reciply 1.1.8+ Fix from $2,3002023-10-17 HIGH 7.2 CVE-2023-35018 IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382. Security Verify Governance 10.0.2+ Fix from $1,9502023-10-16 CRITICAL 9.8 CVE-2023-45856 qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI. Qdpm No fix yet Fix from $2,3002023-10-14 MEDIUM 5.3 CVE-2023-44962 File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl… Koha Library Software after 23.05.04 Fix from $1,6002023-10-11 HIGH 8.8 CVE-2023-5492 A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to … Smart S45f Firmware after 20230928 Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-5493 A vulnerability has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as cri… Smart S45f Firmware after 20230928 Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-5491 A vulnerability, which was classified as critical, has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform u… Smart S45f Firmware after 20230928 Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-5489 A vulnerability classified as critical has been found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 2023092… Smart S45f Firmware after 20230928 Fix from $1,9502023-10-10