Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2023-24269 An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Z… Textpattern No fix yet Fix from $1,9502023-04-28 CRITICAL 9.8 CVE-2023-29268 The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote… Spotfire Statistics Services 11.4.11+ Fix from $2,3002023-04-26 HIGH 7.2 CVE-2022-25277 Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenam… Drupal 9.3.19 / 9.4.3+ Fix from $1,9502023-04-26 HIGH 8.8 CVE-2023-30266 CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. Cltphp after 6.0 Fix from $1,9502023-04-26 HIGH 7.2 CVE-2022-36769 IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed wit… Cloud Pak For Data Mitigation only Fix from $1,9502023-04-26 HIGH 7.8 CVE-2023-26098 An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted file to execute arbitrary co… Apsal Mitigation only Fix from $1,9502023-04-25 CRITICAL 9.0 CVE-2023-30613 Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior t… Kiwi Tcms 12.2+ Fix from $2,3002023-04-24 HIGH 7.2 CVE-2023-1731 In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an re… Lantime Firmware 7.06.013+ Fix from $1,9502023-04-24 CRITICAL 9.8 CVE-2023-25132 Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier,… Powerpanel after 4.8.6 Fix from $2,3002023-04-24 CRITICAL 9.8 CVE-2023-2246 A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code… Online Pizza Ordering System No fix yet Fix from $2,3002023-04-23 MEDIUM 6.3 CVE-2023-2245 A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/cont… Hansuncms No fix yet Fix from $1,6002023-04-22 CRITICAL 9.8 CVE-2023-28962 An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, netw… Junos 19.4+ Fix from $2,3002023-04-17 HIGH 8.8 CVE-2023-27755 go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download. Go Bbs No fix yet Fix from $1,9502023-04-17 CRITICAL 9.8 CVE-2022-34128EPSS 8% The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php. Positions 6.0.1+ Fix from $2,3002023-04-16 HIGH 8.8 CVE-2023-29625 Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitr… Employee Performance Evaluation System No fix yet Fix from $1,9502023-04-14 HIGH 8.8 CVE-2023-29627 Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a cr… Online Pizza Ordering No fix yet Fix from $1,9502023-04-14 HIGH 8.8 CVE-2023-29621 Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via … Purchase Order Management No fix yet Fix from $1,9502023-04-14 HIGH 8.8 CVE-2023-2034EPSS 73% Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14. Froxlor 2.0.14+ Fix from $1,9502023-04-14 HIGH 7.2 CVE-2023-26852 An arbitrary file upload vulnerability in the upload plugin of Textpattern v4.8.8 and below allows attackers to execute arbitrary code by uploading a… Textpattern after 4.8.8 Fix from $1,9502023-04-12 CRITICAL 9.8 CVE-2020-19802 File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter. Doyocms Mitigation only Fix from $2,3002023-04-11 HIGH 7.5 CVE-2023-27179EPSS 61% GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php. Gdidees Cms after 3.9.1 Fix from $1,9502023-04-11 CRITICAL 9.8 CVE-2023-27178 An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file. Gdidees Cms Mitigation only Fix from $2,3002023-04-10 HIGH 7.2 CVE-2023-1970 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in yuan1994 tpAdmin 1.3.12. This issue affects t… Tpadmin No fix yet Fix from $1,9502023-04-10 CRITICAL 9.8 CVE-2023-29375 An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 b… Sitefinity 13.3.7646 / 14.0.7736+ Fix from $2,3002023-04-10 HIGH 8.8 CVE-2023-1406 The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote c… Jetengine For Elementor 3.1.3.1+ Fix from $1,9502023-04-10 CRITICAL 9.8 CVE-2023-27602 In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recomme… Linkis after 1.3.1 Fix from $2,3002023-04-10 CRITICAL 9.8 CVE-2023-27033 Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontContro… Cdesigner 3.2.2+ Fix from $2,3002023-04-07 CRITICAL 9.8 CVE-2023-1942 A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is a… Online Computer And Laptop Store No fix yet Fix from $2,3002023-04-07 CRITICAL 9.8 CVE-2023-24720 An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file. Readium Js No fix yet Fix from $2,3002023-04-05 HIGH 7.2 CVE-2023-0670 Ulearn version a5a7ca20de859051ea0470542844980a66dfc05d allows an attacker with administrator permissions to obtain remote code execution on the serv… Ulearn Mitigation only Fix from $1,9502023-04-05