Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-45476
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is…
Tiny File Manager
No fix yet
CRITICAL 9.8
CVE-2022-41705
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the applica…
Badaso
No fix yet
HIGH 7.2
CVE-2022-45039
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP …
Wbce Cms
No fix yet
HIGH 8.8
CVE-2021-43258EPSS 11%
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot h…
Churchinfo
after 1.3.0
CRITICAL 9.8
CVE-2020-23591
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files thro…
Op Xt71000n Firmware
Mitigation only
HIGH 7.8
CVE-2022-2791
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will …
Proficy
after 9.00
HIGH 7.2
CVE-2022-30529
File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files vi…
Isic.lk
after 2018-02-13
CRITICAL 9.8
CVE-2022-42698
Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
Api2cart Bridge Connector
Mitigation only
HIGH 8.8
CVE-2022-40200
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
Wpforo Forum
after 2.0.9
MEDIUM 6.7
CVE-2022-43192
An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code …
Dedecms
No fix yet
HIGH 8.8
CVE-2022-44384EPSS 5%
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.
Rconfig
No fix yet
CRITICAL 9.8
CVE-2022-43234
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.
Hoosk
No fix yet
CRITICAL 9.8
CVE-2022-43265
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary …
Canteen Management System
Mitigation only
HIGH 7.2
CVE-2022-43146
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via …
Canteen Management System
Mitigation only
HIGH 8.8
CVE-2022-3944
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the fil…
Erp
No fix yet
CRITICAL 10.0
CVE-2022-40981
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of t…
Remote Access Server Firmware
after 4.5.0
CRITICAL 9.8
CVE-2022-43074
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows…
Ayacms
No fix yet
CRITICAL 9.8
CVE-2022-39036
The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit t…
Agentflow
Mitigation only
HIGH 7.2
CVE-2022-43277
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulne…
Canteen Management System
No fix yet
CRITICAL 9.8
CVE-2022-40797
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4,…
Roxy Fileman
No fix yet
HIGH 7.2
CVE-2022-43050
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. T…
Online Tours And Travels Management System
No fix yet
CRITICAL 9.8
CVE-2022-44048
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution b…
D8s Urls
Mitigation only
CRITICAL 9.8
CVE-2022-44049
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution…
D8s Python
Mitigation only
CRITICAL 9.8
CVE-2022-44050
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execu…
D8s Networking
No fix yet
CRITICAL 9.8
CVE-2022-44051
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution …
D8s Stats
Mitigation only
CRITICAL 9.8
CVE-2022-44052
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution …
D8s Dates
Mitigation only
CRITICAL 9.8
CVE-2022-44053
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execu…
D8s Networking
Mitigation only
CRITICAL 9.8
CVE-2022-44054
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution ba…
D8s Xml
Mitigation only
CRITICAL 9.8
CVE-2022-43303
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code executio…
D8s Strings
Mitigation only
CRITICAL 9.8
CVE-2022-43304
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution …
D8s Timer
Mitigation only