Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2023-5490 A vulnerability classified as critical was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. Th… Smart S45f Firmware after 20230928 Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-5488 A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928. It has been rated as crit… Smart S45f Firmware after 20230928 Fix from $1,9502023-10-10 MEDIUM 5.4 CVE-2023-44763 Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE:… Concrete Cms No fix yet Fix from $1,6002023-10-10 CRITICAL 9.8 CVE-2023-43696 Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the … Apu0200 Firmware 4.0.0.6+ Fix from $2,3002023-10-09 HIGH 8.8 CVE-2023-45353 Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the… Unify Openscape Common Management Mitigation only Fix from $1,9502023-10-09 HIGH 8.8 CVE-2023-44061 File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in… Simple And Nice Shopping Cart Script No fix yet Fix from $1,9502023-10-06 CRITICAL 9.8 CVE-2023-43269 pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability. Pigcms after 7.0 Fix from $2,3002023-10-05 HIGH 8.8 CVE-2023-43321 File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget funct… Dcfw 1800 Sdc Firmware No fix yet Fix from $1,9502023-10-04 HIGH 7.8 CVE-2023-43838 An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG f… Personal Management System No fix yet Fix from $1,9502023-10-04 CRITICAL 9.8 CVE-2023-44973 An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via upload… Emlog No fix yet Fix from $2,3002023-10-03 CRITICAL 9.8 CVE-2023-44974EPSS 19% An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploadin… Emlog No fix yet Fix from $2,3002023-10-03 HIGH 8.8 CVE-2023-4817 This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising… Et 7060 Firmware Mitigation only Fix from $1,9502023-10-03 CRITICAL 9.8 CVE-2022-47893 There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a w… Netman 204 Firmware Mitigation only Fix from $2,3002023-10-03 HIGH 8.8 CVE-2023-4097 The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attac… Qsige Mitigation only Fix from $1,9502023-10-03 CRITICAL 9.8 CVE-2023-44008 File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. Mojoportal No fix yet Fix from $2,3002023-10-02 CRITICAL 9.8 CVE-2023-44009 File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. Mojoportal No fix yet Fix from $2,3002023-10-02 CRITICAL 9.8 CVE-2023-5227 Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8. Phpmyfaq 3.1.8+ Fix from $2,3002023-09-30 HIGH 8.8 CVE-2023-5284 A vulnerability classified as critical has been found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file uplo… Engineers Online Portal No fix yet Fix from $1,9502023-09-29 CRITICAL 9.8 CVE-2023-5277 A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown proc… Engineers Online Portal No fix yet Fix from $2,3002023-09-29 HIGH 8.8 CVE-2023-5262 A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is the function isImg of the fi… Rapidcms No fix yet Fix from $1,9502023-09-29 HIGH 8.8 CVE-2023-43740 Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an au… Online Book Store Project No fix yet Fix from $1,9502023-09-28 HIGH 8.8 CVE-2023-5185 Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing a… Gym Management System Project No fix yet Fix from $1,9502023-09-28 HIGH 8.8 CVE-2023-43226 An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading … Dedecms after 5.7.111 Fix from $1,9502023-09-28 CRITICAL 9.1 CVE-2022-47186 There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, w… Cs141 Firmware 2.06+ Fix from $2,3002023-09-28 HIGH 8.8 CVE-2023-38874EPSS 28% A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). A… Economizzer No fix yet Fix from $1,9502023-09-28 CRITICAL 9.1 CVE-2023-42462 GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $2,3002023-09-27 HIGH 7.2 CVE-2023-40219 Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory. Welcart E Commerce after 2.8.21 Fix from $1,9502023-09-27 HIGH 7.2 CVE-2023-39377 SiberianCMS - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dang… Siberiancms 4.20.44 / 5.0.4+ Fix from $1,9502023-09-27 HIGH 8.8 CVE-2023-5154EPSS 15% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-8000 up to 20151231 and classified as critical. This vulnerability affec… Dar 8000 Firmware after 2015-12-31 Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-5150EPSS 23% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an … Dar 7000 Firmware after 2015-12-31 Fix from $1,9502023-09-25