Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2023-33498 alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file. Alist 3.16.3+ Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2020-36705EPSS 7% The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image fun… Adning Advertising 1.5.6+ Fix from $2,3002023-06-07 HIGH 8.8 CVE-2021-4382 The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function … Recently 3.0.5+ Fix from $1,9502023-06-07 HIGH 8.8 CVE-2022-4949 The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versio… Adsanity 1.8.2+ Fix from $1,9502023-06-07 HIGH 8.8 CVE-2023-33601 An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file. Phpok No fix yet Fix from $1,9502023-06-07 HIGH 8.8 CVE-2021-4354 The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader … Pwa For Wp \& Amp 1.7.33+ Fix from $1,9502023-06-07 HIGH 8.8 CVE-2020-36701 The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_… Page Builder King Composer after 2.9.3 Fix from $1,9502023-06-07 CRITICAL 9.8 CVE-2016-15033 The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-co… Delete All Comments after 2.0 Fix from $2,3002023-06-07 CRITICAL 9.8 CVE-2019-25138 The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images fun… User Submitted Posts after 20190312 Fix from $2,3002023-06-07 HIGH 7.2 CVE-2023-33569 Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user. Faculty Evaluation System No fix yet Fix from $1,9502023-06-06 CRITICAL 9.8 CVE-2023-32628 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extensi… Webaccess\/scada after 9.1.3 Fix from $2,3002023-06-06 HIGH 7.2 CVE-2023-22450 In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script fi… Webaccess\/scada after 9.1.3 Fix from $1,9502023-06-06 HIGH 7.5 CVE-2020-19028 *File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php… Emlog No fix yet Fix from $1,9502023-06-05 CRITICAL 9.8 CVE-2023-29631 PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php. Jms Slider Mitigation only Fix from $2,3002023-06-05 CRITICAL 9.8 CVE-2023-33386 MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background. Marsctf No fix yet Fix from $2,3002023-06-05 CRITICAL 9.8 CVE-2023-3061 A vulnerability was found in code-projects Agro-School Management System 1.0 and classified as critical. This issue affects some unknown processing o… Agro School Management System No fix yet Fix from $2,3002023-06-02 HIGH 8.8 CVE-2023-3032 Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user … Mobatime Web Application after 06.7.22 Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-28699 Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An authenticated remote attacker … Fantasy Mitigation only Fix from $1,9502023-06-02 MEDIUM 6.8 CVE-2023-28700 OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with adminis… Omicard Edm Mitigation only Fix from $1,6002023-06-02 HIGH 7.3 CVE-2023-2063 Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP modul… Fx5 Enet\/ip Firmware Mitigation only Fix from $1,9502023-06-02 CRITICAL 9.8 CVE-2014-125104 A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the func… Vaultpress 1.6.1+ Fix from $2,3002023-06-01 CRITICAL 9.8 CVE-2023-33508 KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE). Via Go2 Firmware 4.0.1.1326+ Fix from $2,3002023-05-31 HIGH 8.8 CVE-2023-28353 An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on … Insight No fix yet Fix from $1,9502023-05-31 MEDIUM 6.5 CVE-2023-32689 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 5.4.4 and 6.1.1 are vulnera… Parse Server 5.4.4 / 6.1.1+ Fix from $1,6002023-05-30 CRITICAL 9.8 CVE-2023-2924EPSS 24% A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this issue is some unknown functio… Simfield Firmware after 1.80.00.00 Fix from $2,3002023-05-27 MEDIUM 5.4 CVE-2023-32686 Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans,… Kiwi Tcms after 12.2 Fix from $1,6002023-05-27 MEDIUM 6.5 CVE-2023-22504 Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload att… Confluence Server 7.13.17 / 7.19.9+ Fix from $1,6002023-05-25 HIGH 8.8 CVE-2023-2888 A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&… Phpok No fix yet Fix from $1,9502023-05-25 CRITICAL 9.8 CVE-2023-29721 SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution. Sofawiki after 3.8.9 Fix from $2,3002023-05-24 CRITICAL 9.8 CVE-2023-28409 Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker t… Mw Wp Form after 4.4.2 Fix from $2,3002023-05-23