Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2023-27397
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and serv…
Mailform
1.1.9+
CRITICAL 9.8
CVE-2023-31689EPSS 20%
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter an…
Wcms
No fix yet
CRITICAL 9.8
CVE-2023-2712
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows …
Rental Module
23.05.15+
CRITICAL 9.8
CVE-2023-30333
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code …
Perfreeblog
No fix yet
CRITICAL 9.8
CVE-2023-2776
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The m…
Simple Photo Gallery
Mitigation only
CRITICAL 9.8
CVE-2023-31903
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
Guppy
No fix yet
CRITICAL 9.8
CVE-2023-2738
A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. …
Tongda Office Anywhere
No fix yet
CRITICAL 9.8
CVE-2023-31857
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is …
Online Computer And Laptop Store
No fix yet
HIGH 8.8
CVE-2023-31576
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
Serendipity
No fix yet
CRITICAL 9.8
CVE-2023-30247
File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the u…
Storage Unit Rental Management System
No fix yet
HIGH 8.8
CVE-2023-29657
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary cod…
Extplorer
No fix yet
HIGH 8.8
CVE-2021-34076
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
Phpok
No fix yet
CRITICAL 9.8
CVE-2023-2648EPSS 28%
A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/…
E Office
No fix yet
HIGH 8.8
CVE-2023-29930
An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login…
Tftp Server
Mitigation only
HIGH 7.2
CVE-2023-28128EPSS 85%
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve…
Avalanche
after 6.3.4.153
CRITICAL 9.8
CVE-2023-24507
AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.
Agilepoint Nx
Mitigation only
HIGH 8.8
CVE-2020-22755
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-319…
Mcms
No fix yet
HIGH 7.8
CVE-2021-27280
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.
Mblog
No fix yet
HIGH 7.2
CVE-2021-28998
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
Cms Made Simple
after 2.2.15
CRITICAL 9.8
CVE-2023-30185
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
Crmeb
after 4.6.0
CRITICAL 9.8
CVE-2023-30090
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows atta…
Semcms
Mitigation only
CRITICAL 9.8
CVE-2023-30122
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to exec…
Online Food Ordering System
No fix yet
CRITICAL 9.8
CVE-2023-30264
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.
Cltphp
after 6.0
CRITICAL 9.8
CVE-2023-2523EPSS 33%
A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App…
E Office
No fix yet
HIGH 8.8
CVE-2022-47878EPSS 36%
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the loca…
Jedox
No fix yet
HIGH 7.2
CVE-2023-0924
The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (suc…
Popup
1.1+
CRITICAL 9.8
CVE-2023-29635
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function covers…
Antabot White Jotter
Patch available
CRITICAL 9.8
CVE-2022-45802
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…
Streampark
2.0.0+
HIGH 8.8
CVE-2023-2424
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uplo…
Dedecms
No fix yet
HIGH 7.2
CVE-2023-2419
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the function videoUpload of the fil…
Crmeb
No fix yet