Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2022-34483 An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe… Firefox 102.0+ Fix from $1,9502022-12-22 HIGH 7.8 CVE-2022-0517 Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to lau… Vpn 2.7.1+ Fix from $1,9502022-12-22 CRITICAL 9.8 CVE-2022-46102 AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php Ayacms No fix yet Fix from $2,3002022-12-22 CRITICAL 9.8 CVE-2022-45966 here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. Classcms No fix yet Fix from $2,3002022-12-22 CRITICAL 9.8 CVE-2022-46020EPSS 39% WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. Wbce Cms No fix yet Fix from $2,3002022-12-20 HIGH 7.2 CVE-2022-46135 In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and co… Aerocms No fix yet Fix from $1,9502022-12-16 HIGH 7.8 CVE-2022-45338 An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterp… Exact Synergy Mitigation only Fix from $1,9502022-12-15 HIGH 8.8 CVE-2020-20588 File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avata… Ibarn No fix yet Fix from $1,9502022-12-15 HIGH 8.8 CVE-2022-4506 Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2. Openemr 7.0.0.2+ Fix from $1,9502022-12-15 HIGH 8.8 CVE-2022-41267 SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objec… Business Objects Business Intelligence Platform Mitigation only Fix from $1,9502022-12-13 HIGH 7.2 CVE-2022-45275EPSS 15% An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to… Dynamic Transaction Queuing System No fix yet Fix from $1,9502022-12-12 HIGH 7.5 CVE-2022-3912 The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauth… User Registration 2.2.4.1+ Fix from $1,9502022-12-12 HIGH 8.8 CVE-2022-45968 Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one). Alist No fix yet Fix from $1,9502022-12-12 HIGH 8.8 CVE-2022-45759 SENS v1.0 has a file upload vulnerability. Sens No fix yet Fix from $1,9502022-12-12 HIGH 7.8 CVE-2022-46828 In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. Intellij Idea 2022.3+ Fix from $1,9502022-12-08 HIGH 7.2 CVE-2022-45009 Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=up… Online Leave Management System No fix yet Fix from $1,9502022-12-07 CRITICAL 9.8 CVE-2022-45359EPSS 14% Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. Yith Woocommerce Gift Cards after 3.19.0 Fix from $2,3002022-12-06 HIGH 8.8 CVE-2022-45548 AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. Ayacms No fix yet Fix from $1,9502022-12-06 HIGH 8.8 CVE-2022-44289 Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell. Thinkphp No fix yet Fix from $1,9502022-12-06 HIGH 7.2 CVE-2022-45912 An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admi… Collaboration Mitigation only Fix from $1,9502022-12-05 HIGH 8.8 CVE-2022-45771 An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted aud… Pwndoc No fix yet Fix from $1,9502022-12-05 CRITICAL 9.8 CVE-2022-4276 A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-… House Rental System No fix yet Fix from $2,3002022-12-03 CRITICAL 9.8 CVE-2022-4273 A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unk… Human Resource Management System No fix yet Fix from $2,3002022-12-03 CRITICAL 9.8 CVE-2022-4272 A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /p… Warehouse Management System No fix yet Fix from $2,3002022-12-03 CRITICAL 9.8 CVE-2022-36431 An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a… Trufusion 7.9.6.1+ Fix from $2,3002022-12-01 CRITICAL 9.8 CVE-2022-4232 A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The ma… Event Registration System Mitigation only Fix from $2,3002022-11-30 CRITICAL 9.8 CVE-2022-44354 SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. Solarview Compact Firmware No fix yet Fix from $2,3002022-11-29 HIGH 8.8 CVE-2022-38140 Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress. Seo Plugin By Squirrly Seo after 12.1.10 Fix from $1,9502022-11-28 CRITICAL 9.8 CVE-2022-44400 Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info. Purchase Order Management System No fix yet Fix from $2,3002022-11-28 CRITICAL 9.8 CVE-2022-44401 Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php. Online Tours \& Travels Management System No fix yet Fix from $2,3002022-11-28