Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-33498
alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
Alist
3.16.3+
CRITICAL 9.8
CVE-2020-36705EPSS 7%
The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image fun…
Adning Advertising
1.5.6+
HIGH 8.8
CVE-2021-4382
The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fetch_external_image() function …
Recently
3.0.5+
HIGH 8.8
CVE-2022-4949
The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_upload' function in versio…
Adsanity
1.8.2+
HIGH 8.8
CVE-2023-33601
An arbitrary file upload vulnerability in /admin.php?c=upload of phpok v6.4.100 allows attackers to execute arbitrary code via a crafted PHP file.
Phpok
No fix yet
HIGH 8.8
CVE-2021-4354
The PWA for WP & AMP for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pwaforwp_splashscreen_uploader …
Pwa For Wp \& Amp
1.7.33+
HIGH 8.8
CVE-2020-36701
The Page Builder: KingComposer plugin for WordPress is vulnerable to Arbitrary File Uploads in versions up to, and including, 2.9.3 via the 'process_…
Page Builder King Composer
after 2.9.3
CRITICAL 9.8
CVE-2016-15033
The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-co…
Delete All Comments
after 2.0
CRITICAL 9.8
CVE-2019-25138
The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images fun…
User Submitted Posts
after 20190312
HIGH 7.2
CVE-2023-33569
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.
Faculty Evaluation System
No fix yet
CRITICAL 9.8
CVE-2023-32628
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extensi…
Webaccess\/scada
after 9.1.3
HIGH 7.2
CVE-2023-22450
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script fi…
Webaccess\/scada
after 9.1.3
HIGH 7.5
CVE-2020-19028
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php…
Emlog
No fix yet
CRITICAL 9.8
CVE-2023-29631
PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.
Jms Slider
Mitigation only
CRITICAL 9.8
CVE-2023-33386
MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.
Marsctf
No fix yet
CRITICAL 9.8
CVE-2023-3061
A vulnerability was found in code-projects Agro-School Management System 1.0 and classified as critical. This issue affects some unknown processing o…
Agro School Management System
No fix yet
HIGH 8.8
CVE-2023-3032
Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user …
Mobatime Web Application
after 06.7.22
HIGH 8.8
CVE-2023-28699
Wade Graphic Design FANTSY has a vulnerability of insufficient filtering for file type in its file update function. An authenticated remote attacker …
Fantasy
Mitigation only
MEDIUM 6.8
CVE-2023-28700
OMICARD EDM backend system’s file uploading function does not restrict upload of file with dangerous type. A local area network attacker with adminis…
Omicard Edm
Mitigation only
HIGH 7.3
CVE-2023-2063
Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP modul…
Fx5 Enet\/ip Firmware
Mitigation only
CRITICAL 9.8
CVE-2014-125104
A vulnerability was found in VaultPress Plugin up to 1.6.0 on WordPress. It has been declared as critical. Affected by this vulnerability is the func…
Vaultpress
1.6.1+
CRITICAL 9.8
CVE-2023-33508
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
Via Go2 Firmware
4.0.1.1326+
HIGH 8.8
CVE-2023-28353
An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on …
Insight
No fix yet
MEDIUM 6.5
CVE-2023-32689
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 5.4.4 and 6.1.1 are vulnera…
Parse Server
5.4.4 / 6.1.1+
CRITICAL 9.8
CVE-2023-2924EPSS 24%
A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this issue is some unknown functio…
Simfield Firmware
after 1.80.00.00
MEDIUM 5.4
CVE-2023-32686
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans,…
Kiwi Tcms
after 12.2
MEDIUM 6.5
CVE-2023-22504
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload att…
Confluence Server
7.13.17 / 7.19.9+
HIGH 8.8
CVE-2023-2888
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&…
Phpok
No fix yet
CRITICAL 9.8
CVE-2023-29721
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
Sofawiki
after 3.8.9
CRITICAL 9.8
CVE-2023-28409
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker t…
Mw Wp Form
after 4.4.2