Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-47854
i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.
I Librarian
No fix yet
CRITICAL 9.8
CVE-2022-48006
An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is expl…
Taocms
No fix yet
CRITICAL 9.8
CVE-2022-43979
There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha…
Pandora Fms
766+
HIGH 7.2
CVE-2021-41231
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and…
Magento
19.4.22 / 20.0.19+
CRITICAL 9.8
CVE-2022-48008
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
Limesurvey
No fix yet
HIGH 8.8
CVE-2023-0455EPSS 6%
Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.
Bumsys
Patch available
CRITICAL 9.8
CVE-2022-47615EPSS 5%
Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
Learnpress
4.2.0+
HIGH 8.8
CVE-2022-47042
MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.
Mcms
No fix yet
CRITICAL 9.8
CVE-2022-40037
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.
Javaweb Blog
No fix yet
HIGH 8.8
CVE-2022-40035
File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escalated privileges via the /uplo…
Blog Ssm
No fix yet
HIGH 8.8
CVE-2023-22726
act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitiz…
Act
0.2.40+
CRITICAL 9.8
CVE-2023-23607
erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arb…
Dasherr
1.05.00+
CRITICAL 9.8
CVE-2021-26642
When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insuf…
Xpressengine
3.0.14+
MEDIUM 5.5
CVE-2023-20040
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial o…
Network Services Orchestrator
5.4.7 / 5.5.6+
HIGH 8.8
CVE-2022-47766
PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
Popojicms
No fix yet
MEDIUM 6.5
CVE-2022-46660
An unauthorized user could alter or write files with full control over the path and content of the file.
Proficy Historian
2023+
HIGH 7.2
CVE-2023-22851
Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call.
Tiki
24.2+
HIGH 7.8
CVE-2022-42287
NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances…
Bmc
00.19.07+
CRITICAL 9.8
CVE-2023-0257
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an u…
Online Food Ordering System
Mitigation only
HIGH 8.8
CVE-2022-46610EPSS 18%
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to exec…
Wukong Crm
No fix yet
HIGH 7.2
CVE-2022-44036
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execu…
B2evolution Cms
No fix yet
HIGH 8.8
CVE-2022-43436
The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general us…
Easy Test
Mitigation only
HIGH 8.8
CVE-2022-48194EPSS 33%
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uplo…
Tl Wr902ac Firmware
after 3.0.9.1
HIGH 7.2
CVE-2022-45427
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a spe…
Dss Express
Patch available
HIGH 7.2
CVE-2022-4732EPSS 38%
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
Microweber
after 1.3.1
CRITICAL 9.8
CVE-2022-45896
Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx ca…
Planet Estream
6.72.10.07+
HIGH 8.8
CVE-2022-4665
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.
Ampache
5.5.6+
CRITICAL 9.8
CVE-2022-46493
Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.
Nbnbk
No fix yet
HIGH 7.8
CVE-2022-45415
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with …
Firefox
107.0+
HIGH 8.8
CVE-2022-34482
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe…
Firefox
102.0+