Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2023-5147EPSS 27% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been classified as critical. This affects an unkn… Dar 7000 Firmware after 2015-12-31 Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-5148EPSS 31% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231. It has been declared as critical. This vuln… Dar 7000 Firmware after 2015-12-31 Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-5149EPSS 21% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. This issue affects some u… Dar 7000 Firmware after 2015-12-31 Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-5146EPSS 33% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 and DAR-8000 up to 20151231 and classified as critical. Affected by this… Dar 7000 Firmware after 20151231 Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-5145EPSS 34% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000 up to 20151231 and classified as critical. Affected by this vulnera… Dar 7000 Firmware after 20151231 Fix from $1,9502023-09-25 HIGH 8.8 CVE-2023-5144EPSS 6% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected… Dar 7000 Firmware after 20151231 Fix from $1,9502023-09-24 MEDIUM 5.3 CVE-2023-40183 DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability that allows an attacker to to… Dataease 1.18.11+ Fix from $1,6002023-09-21 HIGH 8.8 CVE-2023-42331 A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component. Elite Cms No fix yet Fix from $1,9502023-09-20 HIGH 8.8 CVE-2023-42335 Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the ad… Crew No fix yet Fix from $1,9502023-09-20 HIGH 8.1 CVE-2023-43497 In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default… Jenkins 2.414.2 / 2.424+ Fix from $1,9502023-09-20 CRITICAL 9.8 CVE-2023-43478EPSS 17% fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware… Arcadyan Lh1000 Firmware 0.18.15r+ Fix from $2,3002023-09-20 HIGH 7.8 CVE-2023-41902 An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting … Macupdater 2.3.8 / 3.1.2+ Fix from $1,9502023-09-20 HIGH 7.8 CVE-2023-43619 An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized_k… Croc after 9.6.5 Fix from $1,9502023-09-20 HIGH 8.8 CVE-2023-38887 File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information… Dolibarr Erp\/crm after 17.0.1 Fix from $1,9502023-09-20 HIGH 8.8 CVE-2023-36319 File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-in… Openupload No fix yet Fix from $1,9502023-09-20 CRITICAL 9.8 CVE-2023-5034 A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.p… My Food Recipe Mitigation only Fix from $2,3002023-09-18 CRITICAL 9.8 CVE-2023-4988 A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of the file index.php?module=sys… Laiketui Mitigation only Fix from $2,3002023-09-15 HIGH 8.8 CVE-2023-42180 An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file. Lenosp after 1.2.0 Fix from $1,9502023-09-14 MEDIUM 5.4 CVE-2023-30962 The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Go… Gotham Cerberus 100.230704.0-27-g031dd58+ Fix from $1,6002023-09-12 CRITICAL 9.8 CVE-2023-40784 DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. Dedecms Mitigation only Fix from $2,3002023-09-12 CRITICAL 9.8 CVE-2023-2071EPSS 11% Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t… Factorytalk View after 13.0 Fix from $2,3002023-09-12 HIGH 8.8 CVE-2023-40731 A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. … Qms Automotive 12.39+ Fix from $1,9502023-09-12 HIGH 7.3 CVE-2023-42472 Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows … Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502023-09-12 MEDIUM 6.1 CVE-2023-41564 An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a … Cockpit Mitigation only Fix from $1,6002023-09-08 HIGH 8.8 CVE-2023-39424 A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such… Internet Reservation Module Next Generation Mitigation only Fix from $1,9502023-09-07 CRITICAL 9.8 CVE-2023-41009 File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization fie… Bolo Solo Mitigation only Fix from $2,3002023-09-05 HIGH 7.2 CVE-2023-3375 Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3… Bookreen 3.0.0+ Fix from $1,9502023-09-05 HIGH 8.8 CVE-2023-41108 TEF portal 2023-07-17 is vulnerable to authenticated remote code execution. Tef Portal No fix yet Fix from $1,9502023-09-05 CRITICAL 9.8 CVE-2023-4739 A vulnerability, which was classified as critical, has been found in Byzoro Smart S85F Management Platform up to 20230820. Affected by this issue is … Smart S85f Firmware after 20230820 Fix from $2,3002023-09-03 CRITICAL 9.8 CVE-2023-40980 File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and… Dwsurvey after 3.2.0 Fix from $2,3002023-09-01