Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2022-45476 Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is… Tiny File Manager No fix yet Fix from $2,3002022-11-25 CRITICAL 9.8 CVE-2022-41705 Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the applica… Badaso No fix yet Fix from $2,3002022-11-25 HIGH 7.2 CVE-2022-45039 An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP … Wbce Cms No fix yet Fix from $1,9502022-11-25 HIGH 8.8 CVE-2021-43258EPSS 11% CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot h… Churchinfo after 1.3.0 Fix from $1,9502022-11-23 CRITICAL 9.8 CVE-2020-23591 A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files thro… Op Xt71000n Firmware Mitigation only Fix from $2,3002022-11-23 HIGH 7.8 CVE-2022-2791 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will … Proficy after 9.00 Fix from $1,9502022-11-22 HIGH 7.2 CVE-2022-30529 File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files vi… Isic.lk after 2018-02-13 Fix from $1,9502022-11-22 CRITICAL 9.8 CVE-2022-42698 Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress. Api2cart Bridge Connector Mitigation only Fix from $2,3002022-11-18 HIGH 8.8 CVE-2022-40200 Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. Wpforo Forum after 2.0.9 Fix from $1,9502022-11-17 MEDIUM 6.7 CVE-2022-43192 An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code … Dedecms No fix yet Fix from $1,6002022-11-17 HIGH 8.8 CVE-2022-44384EPSS 5% An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file. Rconfig No fix yet Fix from $1,9502022-11-17 CRITICAL 9.8 CVE-2022-43234 An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file. Hoosk No fix yet Fix from $2,3002022-11-16 CRITICAL 9.8 CVE-2022-43265 An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary … Canteen Management System Mitigation only Fix from $2,3002022-11-15 HIGH 7.2 CVE-2022-43146 An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via … Canteen Management System Mitigation only Fix from $1,9502022-11-14 HIGH 8.8 CVE-2022-3944 A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the fil… Erp No fix yet Fix from $1,9502022-11-11 CRITICAL 10.0 CVE-2022-40981 All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of t… Remote Access Server Firmware after 4.5.0 Fix from $2,3002022-11-10 CRITICAL 9.8 CVE-2022-43074 AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows… Ayacms No fix yet Fix from $2,3002022-11-10 CRITICAL 9.8 CVE-2022-39036 The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit t… Agentflow Mitigation only Fix from $2,3002022-11-10 HIGH 7.2 CVE-2022-43277 Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulne… Canteen Management System No fix yet Fix from $1,9502022-11-09 CRITICAL 9.8 CVE-2022-40797 Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4,… Roxy Fileman No fix yet Fix from $2,3002022-11-09 HIGH 7.2 CVE-2022-43050 Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. T… Online Tours And Travels Management System No fix yet Fix from $1,9502022-11-07 CRITICAL 9.8 CVE-2022-44048 The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution b… D8s Urls Mitigation only Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-44049 The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution… D8s Python Mitigation only Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-44050 The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execu… D8s Networking No fix yet Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-44051 The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution … D8s Stats Mitigation only Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-44052 The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution … D8s Dates Mitigation only Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-44053 The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execu… D8s Networking Mitigation only Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-44054 The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution ba… D8s Xml Mitigation only Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-43303 The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code executio… D8s Strings Mitigation only Fix from $2,3002022-11-07 CRITICAL 9.8 CVE-2022-43304 The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution … D8s Timer Mitigation only Fix from $2,3002022-11-07