Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2023-24269
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Z…
Textpattern
No fix yet
CRITICAL 9.8
CVE-2023-29268
The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote…
Spotfire Statistics Services
11.4.11+
HIGH 7.2
CVE-2022-25277
Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenam…
Drupal
9.3.19 / 9.4.3+
HIGH 8.8
CVE-2023-30266
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
Cltphp
after 6.0
HIGH 7.2
CVE-2022-36769
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit…
Cloud Pak For Data
Mitigation only
HIGH 7.8
CVE-2023-26098
An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted file to execute arbitrary co…
Apsal
Mitigation only
CRITICAL 9.0
CVE-2023-30613
Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior t…
Kiwi Tcms
12.2+
HIGH 7.2
CVE-2023-1731
In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an re…
Lantime Firmware
7.06.013+
CRITICAL 9.8
CVE-2023-25132
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier,…
Powerpanel
after 4.8.6
CRITICAL 9.8
CVE-2023-2246
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code…
Online Pizza Ordering System
No fix yet
MEDIUM 6.3
CVE-2023-2245
A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/cont…
Hansuncms
No fix yet
CRITICAL 9.8
CVE-2023-28962
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, netw…
Junos
19.4+
HIGH 8.8
CVE-2023-27755
go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download.
Go Bbs
No fix yet
CRITICAL 9.8
CVE-2022-34128EPSS 8%
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
Positions
6.0.1+
HIGH 8.8
CVE-2023-29625
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitr…
Employee Performance Evaluation System
No fix yet
HIGH 8.8
CVE-2023-29627
Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a cr…
Online Pizza Ordering
No fix yet
HIGH 8.8
CVE-2023-29621
Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via …
Purchase Order Management
No fix yet
HIGH 8.8
CVE-2023-2034EPSS 73%
Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.
Froxlor
2.0.14+
HIGH 7.2
CVE-2023-26852
An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a…
Textpattern
after 4.8.8
CRITICAL 9.8
CVE-2020-19802
File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.
Doyocms
Mitigation only
HIGH 7.5
CVE-2023-27179EPSS 61%
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.
Gdidees Cms
after 3.9.1
CRITICAL 9.8
CVE-2023-27178
An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.
Gdidees Cms
Mitigation only
HIGH 7.2
CVE-2023-1970
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin 1.3.12. This issue affects t…
Tpadmin
No fix yet
CRITICAL 9.8
CVE-2023-29375
An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 b…
Sitefinity
13.3.7646 / 14.0.7736+
HIGH 8.8
CVE-2023-1406
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote c…
Jetengine For Elementor
3.1.3.1+
CRITICAL 9.8
CVE-2023-27602
In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types.
We recomme…
Linkis
after 1.3.1
CRITICAL 9.8
CVE-2023-27033
Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontContro…
Cdesigner
3.2.2+
CRITICAL 9.8
CVE-2023-1942
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is a…
Online Computer And Laptop Store
No fix yet
CRITICAL 9.8
CVE-2023-24720
An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.
Readium Js
No fix yet
HIGH 7.2
CVE-2023-0670
Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the serv…
Ulearn
Mitigation only