Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2023-20009 A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow… Email Security Appliance 12.5.3-041 / 12.8.1-021+ Fix from $1,9502023-03-01 MEDIUM 6.5 CVE-2023-24045 In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a … Data Science Studio 11.3.2+ Fix from $1,6002023-03-01 HIGH 7.2 CVE-2023-24249 An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file. Laravel Admin No fix yet Fix from $1,9502023-02-27 HIGH 8.8 CVE-2023-26762 Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability. Erp No fix yet Fix from $1,9502023-02-27 HIGH 7.2 CVE-2021-35290 File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /admin/main/mod-blog page. Balero Cms Mitigation only Fix from $1,9502023-02-24 CRITICAL 9.8 CVE-2021-33224 File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file. Umbraco Forms Mitigation only Fix from $2,3002023-02-24 HIGH 8.1 CVE-2023-24317 Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php. Judging Management System Mitigation only Fix from $1,9502023-02-23 CRITICAL 9.8 CVE-2022-39983 File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code. Rd3 No fix yet Fix from $2,3002023-02-22 CRITICAL 9.8 CVE-2022-41217 Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PR… Cloudflow 2.3.2+ Fix from $2,3002023-02-22 HIGH 7.5 CVE-2022-2883 In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service Octopus Server 2022.3.11043 / 2022.4.8401+ Fix from $1,9502023-02-22 HIGH 8.8 CVE-2023-0943 A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the functio… Best Pos Management System Mitigation only Fix from $1,9502023-02-21 CRITICAL 9.8 CVE-2023-0918 A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of … Pharmacy Management System Mitigation only Fix from $2,3002023-02-19 CRITICAL 9.8 CVE-2021-35261 File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote co… Bearadmin No fix yet Fix from $2,3002023-02-17 CRITICAL 9.1 CVE-2023-24530 SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be… Businessobjects Business Intelligence Platform Mitigation only Fix from $2,3002023-02-14 MEDIUM 5.4 CVE-2023-23851 SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages)… Business Planning And Consolidation Mitigation only Fix from $1,6002023-02-14 CRITICAL 9.8 CVE-2023-24646 An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code v… Online Food Ordering System No fix yet Fix from $2,3002023-02-13 HIGH 8.8 CVE-2023-0255 The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to u… Enable Media Replace 4.0.2+ Fix from $1,9502023-02-13 CRITICAL 9.8 CVE-2023-0783 A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of… Ecshop No fix yet Fix from $2,3002023-02-11 CRITICAL 9.8 CVE-2022-45527 File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious file… Institutional Management Website No fix yet Fix from $2,3002023-02-08 CRITICAL 9.8 CVE-2023-24202 Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php. Raffle Draw System No fix yet Fix from $2,3002023-02-06 MEDIUM 5.4 CVE-2023-23937 Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updatin… Pimcore 10.5.16+ Fix from $1,6002023-02-03 HIGH 8.8 CVE-2021-36426 File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php. Phpwcms 1.9.26+ Fix from $1,9502023-02-03 CRITICAL 9.8 CVE-2022-48079 Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploadi… Aapanel Host System No fix yet Fix from $2,3002023-02-02 CRITICAL 9.8 CVE-2023-0651 A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management.… Fastcms Mitigation only Fix from $2,3002023-02-02 HIGH 8.8 CVE-2022-46604EPSS 9% An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP fi… Responsive Filemanager after 9.9.5 Fix from $1,9502023-02-02 HIGH 7.2 CVE-2023-23135 An arbitrary file upload vulnerability in Ftdms v3.1.6 allows attackers to execute arbitrary code via uploading a crafted JPG file. Ftdms No fix yet Fix from $1,9502023-02-01 HIGH 8.8 CVE-2023-24610 NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be by… Nosh Chartingsystem Mitigation only Fix from $1,9502023-02-01 CRITICAL 9.8 CVE-2022-42971 A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a ma… Apc Easy Ups Online Monitoring Software 2.5-ga / 2.5-gs+ Fix from $2,3002023-02-01 CRITICAL 9.1 CVE-2023-0587EPSS 60% A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent… Apex One Mitigation only Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2022-47769 An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the … Fast Checkin Mitigation only Fix from $2,3002023-02-01