Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.5 CVE-2023-20134 Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site sc… Webex Meetings Mitigation only Fix from $1,6002023-04-05 CRITICAL 9.8 CVE-2023-20073EPSS 89% A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthent… Rv340 Firmware after 1.0.03.29 Fix from $2,3002023-04-05 HIGH 7.2 CVE-2023-26857 An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0 allows attackers to execute … Dynamic Transaction Queuing System No fix yet Fix from $1,9502023-04-05 HIGH 8.8 CVE-2023-0265 Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not pro… Community Skeleton No fix yet Fix from $1,9502023-04-04 HIGH 7.8 CVE-2023-26775EPSS 49% File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/up… Monitorr No fix yet Fix from $1,9502023-04-04 CRITICAL 9.8 CVE-2021-31707 Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type. Kitecms Mitigation only Fix from $2,3002023-04-04 HIGH 7.2 CVE-2021-3267 File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function. Kitecms No fix yet Fix from $1,9502023-04-04 CRITICAL 9.8 CVE-2023-1728 Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Inject… Learning Management Systems 23.04.03+ Fix from $2,3002023-04-04 CRITICAL 9.8 CVE-2023-1826 A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of … Online Computer And Laptop Store No fix yet Fix from $2,3002023-04-04 CRITICAL 9.8 CVE-2023-1800 A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload o… Go Fastdfs after 1.4.3 Fix from $2,3002023-04-02 CRITICAL 9.8 CVE-2023-1797 A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.… Otcms No fix yet Fix from $2,3002023-04-02 CRITICAL 9.8 CVE-2022-47190 Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute a… Cs141 Firmware 2.06+ Fix from $2,3002023-03-31 HIGH 8.8 CVE-2022-47191 Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing h… Cs141 Firmware 2.06+ Fix from $1,9502023-03-31 HIGH 7.2 CVE-2023-26830 An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticat… Centrestack 13.5.9808+ Fix from $1,9502023-03-31 HIGH 8.8 CVE-2023-1744 A vulnerability classified as critical was found in IBOS 4.5.5. This vulnerability affects unknown code of the component htaccess Handler. The manipu… Ibos after 4.5.5 Fix from $1,9502023-03-30 CRITICAL 9.8 CVE-2023-1739 A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown… Simple And Beautiful Shopping Cart System Mitigation only Fix from $2,3002023-03-30 CRITICAL 9.8 CVE-2023-1734 A vulnerability classified as critical has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected is an unknown function of t… Young Entrepreneur E Negosyo System Mitigation only Fix from $2,3002023-03-30 HIGH 8.8 CVE-2023-28833 Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to … Nextcloud Server 23.0.14 / 24.0.10+ Fix from $1,9502023-03-30 CRITICAL 9.8 CVE-2023-28731 AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office… Acymailing 8.3.0+ Fix from $2,3002023-03-30 CRITICAL 9.8 CVE-2023-26968 In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthenticated File upload. Atrocore No fix yet Fix from $2,3002023-03-29 CRITICAL 9.8 CVE-2023-1684 A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the file upload/index.php?c=app&a=… Hadsky No fix yet Fix from $2,3002023-03-29 HIGH 8.8 CVE-2023-27246 An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .h… Mk Auth after 23.01k4.9 Fix from $1,9502023-03-28 HIGH 8.8 CVE-2022-3682 A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and upl… Sdm600 1.3.0.1339+ Fix from $1,9502023-03-28 MEDIUM 6.5 CVE-2023-28652 An authenticated malicious user could successfully upload a malicious image could lead to a denial-of-service condition. Ey As525f001 Firmware No fix yet Fix from $1,6002023-03-27 HIGH 7.2 CVE-2023-25828 Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collecti… Pluck 4.7.16+ Fix from $1,9502023-03-27 CRITICAL 9.8 CVE-2023-25909 HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vuln… Oaklouds Portal 2.0-10 / 3.0-10+ Fix from $2,3002023-03-27 CRITICAL 9.8 CVE-2023-25655 baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contain… Basercms 4.7.5+ Fix from $2,3002023-03-23 CRITICAL 9.8 CVE-2023-25654 baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of bas… Basercms 4.7.5+ Fix from $2,3002023-03-23 HIGH 8.8 CVE-2020-19786 File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file. Csz Cms No fix yet Fix from $1,9502023-03-23 MEDIUM 5.4 CVE-2023-23707 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability i… Embed Any Document after 2.7.1 Fix from $1,6002023-03-23