Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2023-27397 Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and serv… Mailform 1.1.9+ Fix from $2,3002023-05-23 CRITICAL 9.8 CVE-2023-31689EPSS 20% In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter an… Wcms No fix yet Fix from $2,3002023-05-22 CRITICAL 9.8 CVE-2023-2712 Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows … Rental Module 23.05.15+ Fix from $2,3002023-05-20 CRITICAL 9.8 CVE-2023-30333 An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code … Perfreeblog No fix yet Fix from $2,3002023-05-18 CRITICAL 9.8 CVE-2023-2776 A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The m… Simple Photo Gallery Mitigation only Fix from $2,3002023-05-17 CRITICAL 9.8 CVE-2023-31903 GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file. Guppy No fix yet Fix from $2,3002023-05-17 CRITICAL 9.8 CVE-2023-2738 A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. … Tongda Office Anywhere No fix yet Fix from $2,3002023-05-16 CRITICAL 9.8 CVE-2023-31857 Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is … Online Computer And Laptop Store No fix yet Fix from $2,3002023-05-16 HIGH 8.8 CVE-2023-31576 An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file. Serendipity No fix yet Fix from $1,9502023-05-16 CRITICAL 9.8 CVE-2023-30247 File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the u… Storage Unit Rental Management System No fix yet Fix from $2,3002023-05-12 HIGH 8.8 CVE-2023-29657 eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary cod… Extplorer No fix yet Fix from $1,9502023-05-12 HIGH 8.8 CVE-2021-34076 File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload. Phpok No fix yet Fix from $1,9502023-05-11 CRITICAL 9.8 CVE-2023-2648EPSS 28% A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/… E Office No fix yet Fix from $2,3002023-05-11 HIGH 8.8 CVE-2023-29930 An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login… Tftp Server Mitigation only Fix from $1,9502023-05-10 HIGH 7.2 CVE-2023-28128EPSS 85% An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve… Avalanche after 6.3.4.153 Fix from $1,9502023-05-09 CRITICAL 9.8 CVE-2023-24507 AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request. Agilepoint Nx Mitigation only Fix from $2,3002023-05-08 HIGH 8.8 CVE-2020-22755 File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-319… Mcms No fix yet Fix from $1,9502023-05-08 HIGH 7.8 CVE-2021-27280 OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. Mblog No fix yet Fix from $1,9502023-05-08 HIGH 7.2 CVE-2021-28998 File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file. Cms Made Simple after 2.2.15 Fix from $1,9502023-05-08 CRITICAL 9.8 CVE-2023-30185 CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. Crmeb after 4.6.0 Fix from $2,3002023-05-08 CRITICAL 9.8 CVE-2023-30090 Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows atta… Semcms Mitigation only Fix from $2,3002023-05-05 CRITICAL 9.8 CVE-2023-30122 An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to exec… Online Food Ordering System No fix yet Fix from $2,3002023-05-05 CRITICAL 9.8 CVE-2023-30264 CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update. Cltphp after 6.0 Fix from $2,3002023-05-04 CRITICAL 9.8 CVE-2023-2523EPSS 33% A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App… E Office No fix yet Fix from $2,3002023-05-04 HIGH 8.8 CVE-2022-47878EPSS 36% Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the loca… Jedox No fix yet Fix from $1,9502023-05-02 HIGH 7.2 CVE-2023-0924 The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (suc… Popup 1.1+ Fix from $1,9502023-05-02 CRITICAL 9.8 CVE-2023-29635 File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function covers… Antabot White Jotter Patch available Fix from $2,3002023-05-01 CRITICAL 9.8 CVE-2022-45802 Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload… Streampark 2.0.0+ Fix from $2,3002023-05-01 HIGH 8.8 CVE-2023-2424 A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uplo… Dedecms No fix yet Fix from $1,9502023-04-29 HIGH 7.2 CVE-2023-2419 A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the fil… Crmeb No fix yet Fix from $1,9502023-04-29