Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-38404
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of fi…
Infoscale Operations Manager
8.0.0.410+
HIGH 7.2
CVE-2023-3692
Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10.
Admidio
4.2.10+
CRITICAL 9.8
CVE-2023-37839
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading …
Dedecms
No fix yet
CRITICAL 9.9
CVE-2023-3342
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation…
User Registration
3.0.2.1+
CRITICAL 9.8
CVE-2023-34136
Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…
Analytics
9.3.2+
HIGH 8.8
CVE-2023-34126
Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This…
Analytics
9.3.2+
CRITICAL 9.8
CVE-2023-37629EPSS 23%
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pi…
Simple Online Piggery Management System
No fix yet
CRITICAL 9.8
CVE-2023-3625
A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. …
Mountain Flood Disaster Prevention Monitoring And Early Warning System
after 2023-07-06
CRITICAL 9.8
CVE-2023-3626
A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System…
Mountain Flood Disaster Prevention Monitoring And Early Warning System
after 20230706
CRITICAL 9.8
CVE-2023-3623
A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as cr…
Mountain Flood Disaster Prevention Monitoring And Early Warning System
after 2023-07-04
CRITICAL 9.8
CVE-2023-37656
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
Websiteguide
No fix yet
CRITICAL 9.8
CVE-2023-37152
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This ha…
Online Art Gallery
No fix yet
HIGH 8.8
CVE-2023-34193
File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via…
Collaboration
Mitigation only
HIGH 8.8
CVE-2023-36969EPSS 49%
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Cms Made Simple
No fix yet
HIGH 8.8
CVE-2020-21861
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
Duxcms
No fix yet
MEDIUM 5.4
CVE-2023-36809
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12…
Kiwi Tcms
12.5+
HIGH 7.8
CVE-2023-37208
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Fire…
Firefox
102.13 / 115.0+
HIGH 8.8
CVE-2023-3503
A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functi…
Shopping Website
No fix yet
CRITICAL 9.8
CVE-2023-3504
A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …
Smartweb Infotech Job Board
Mitigation only
CRITICAL 9.8
CVE-2020-22151
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of t…
Fuel Cms
No fix yet
CRITICAL 9.8
CVE-2020-22153
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in t…
Fuel Cms
No fix yet
HIGH 8.8
CVE-2023-3491
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
Fossbilling
0.5.3+
HIGH 7.2
CVE-2023-32621
WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands …
Wl Wn531ax2 Firmware
2023526+
CRITICAL 9.8
CVE-2020-18432
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
Semcms
Mitigation only
CRITICAL 9.8
CVE-2023-34738
Chemex through 3.7.1 is vulnerable to arbitrary file upload.
Chemex
after 3.7.1
HIGH 7.2
CVE-2023-34736
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
Guantang Equipment Management System
No fix yet
CRITICAL 9.8
CVE-2022-44276
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
Responsive Filemanager
9.12.0+
MEDIUM 6.5
CVE-2023-32525
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affe…
Mobile Security
Patch available
MEDIUM 6.5
CVE-2023-32526
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affe…
Mobile Security
Patch available
CRITICAL 9.8
CVE-2023-33404EPSS 26%
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allow…
Blogengine.net
after 3.3.8.0