Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2022-47854 i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php. I Librarian No fix yet Fix from $2,3002023-01-31 CRITICAL 9.8 CVE-2022-48006 An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is expl… Taocms No fix yet Fix from $2,3002023-01-30 CRITICAL 9.8 CVE-2022-43979 There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha… Pandora Fms 766+ Fix from $2,3002023-01-27 HIGH 7.2 CVE-2021-41231 OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and… Magento 19.4.22 / 20.0.19+ Fix from $1,9502023-01-27 CRITICAL 9.8 CVE-2022-48008 An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file. Limesurvey No fix yet Fix from $2,3002023-01-27 HIGH 8.8 CVE-2023-0455EPSS 6% Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta. Bumsys Patch available Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2022-47615EPSS 5% Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions. Learnpress 4.2.0+ Fix from $2,3002023-01-26 HIGH 8.8 CVE-2022-47042 MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do. Mcms No fix yet Fix from $1,9502023-01-26 CRITICAL 9.8 CVE-2022-40037 An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile. Javaweb Blog No fix yet Fix from $2,3002023-01-26 HIGH 8.8 CVE-2022-40035 File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escalated privileges via the /uplo… Blog Ssm No fix yet Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-22726 act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitiz… Act 0.2.40+ Fix from $1,9502023-01-20 CRITICAL 9.8 CVE-2023-23607 erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arb… Dasherr 1.05.00+ Fix from $2,3002023-01-20 CRITICAL 9.8 CVE-2021-26642 When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insuf… Xpressengine 3.0.14+ Fix from $2,3002023-01-20 MEDIUM 5.5 CVE-2023-20040 A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial o… Network Services Orchestrator 5.4.7 / 5.5.6+ Fix from $1,6002023-01-20 HIGH 8.8 CVE-2022-47766 PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability. Popojicms No fix yet Fix from $1,9502023-01-19 MEDIUM 6.5 CVE-2022-46660 An unauthorized user could alter or write files with full control over the path and content of the file. Proficy Historian 2023+ Fix from $1,6002023-01-18 HIGH 7.2 CVE-2023-22851 Tiki before 24.2 allows lib/importer/tikiimporter_blog_wordpress.php PHP Object Injection by an admin because of an unserialize call. Tiki 24.2+ Fix from $1,9502023-01-14 HIGH 7.8 CVE-2022-42287 NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances… Bmc 00.19.07+ Fix from $1,9502023-01-13 CRITICAL 9.8 CVE-2023-0257 A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an u… Online Food Ordering System Mitigation only Fix from $2,3002023-01-12 HIGH 8.8 CVE-2022-46610EPSS 18% 72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to exec… Wukong Crm No fix yet Fix from $1,9502023-01-10 HIGH 7.2 CVE-2022-44036 In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execu… B2evolution Cms No fix yet Fix from $1,9502023-01-03 HIGH 8.8 CVE-2022-43436 The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general us… Easy Test Mitigation only Fix from $1,9502023-01-03 HIGH 8.8 CVE-2022-48194EPSS 33% TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uplo… Tl Wr902ac Firmware after 3.0.9.1 Fix from $1,9502022-12-30 HIGH 7.2 CVE-2022-45427 Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a spe… Dss Express Patch available Fix from $1,9502022-12-27 HIGH 7.2 CVE-2022-4732EPSS 38% Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2. Microweber after 1.3.1 Fix from $1,9502022-12-27 CRITICAL 9.8 CVE-2022-45896 Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx ca… Planet Estream 6.72.10.07+ Fix from $2,3002022-12-25 HIGH 8.8 CVE-2022-4665 Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6. Ampache 5.5.6+ Fix from $1,9502022-12-23 CRITICAL 9.8 CVE-2022-46493 Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img. Nbnbk No fix yet Fix from $2,3002022-12-22 HIGH 7.8 CVE-2022-45415 When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with … Firefox 107.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-34482 An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe… Firefox 102.0+ Fix from $1,9502022-12-22