Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2022-43305 The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution… D8s Python Mitigation only Fix from $2,3002022-11-07 HIGH 8.8 CVE-2022-43306 The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution … D8s Timer Mitigation only Fix from $1,9502022-11-07 HIGH 8.8 CVE-2022-3537 The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files … Role Based Pricing For Woocommerce 1.6.2+ Fix from $1,9502022-11-07 HIGH 7.2 CVE-2022-43061 Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/traveller… Online Tours \& Travels Management System No fix yet Fix from $1,9502022-11-03 CRITICAL 9.8 CVE-2022-3575 Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using… Frauscher Diagnostic System 102 Mitigation only Fix from $2,3002022-11-02 HIGH 7.2 CVE-2022-43083 An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a craft… Vehicle Booking System No fix yet Fix from $1,9502022-11-01 HIGH 7.2 CVE-2022-43085 An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP … Restaurant Pos System No fix yet Fix from $1,9502022-11-01 HIGH 7.5 CVE-2022-39019 Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the a… Hubshare 3.3.11.3+ Fix from $1,9502022-10-31 HIGH 8.8 CVE-2022-41681 There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es… Formalms 3.2.1+ Fix from $1,9502022-10-31 HIGH 8.8 CVE-2022-42925 There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the role of student) to privilege es… Formalms 3.2.1+ Fix from $1,9502022-10-31 CRITICAL 9.8 CVE-2022-40471EPSS 20% Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functio… Clinic\'s Patient Management System No fix yet Fix from $2,3002022-10-31 CRITICAL 9.8 CVE-2022-3771 A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php … Easyiicms Mitigation only Fix from $2,3002022-10-31 MEDIUM 5.5 CVE-2022-43283 wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. Wabt No fix yet Fix from $1,6002022-10-28 HIGH 7.2 CVE-2022-43231 Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerabilit… Canteen Management System No fix yet Fix from $1,9502022-10-28 HIGH 7.5 CVE-2022-37426 Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection. Opennebula 6.4.2+ Fix from $1,9502022-10-28 HIGH 7.2 CVE-2022-43275 Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This… Canteen Management System No fix yet Fix from $1,9502022-10-28 CRITICAL 9.8 CVE-2022-33859 A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in… Foreseer Electrical Power Monitoring System 7.6+ Fix from $2,3002022-10-28 CRITICAL 10.0 CVE-2021-38397 Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may allow an attacker to remotely ex… C200 Firmware Mitigation only Fix from $2,3002022-10-28 HIGH 7.2 CVE-2022-39977 Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulner… Online Pet Shop We App No fix yet Fix from $1,9502022-10-27 HIGH 7.2 CVE-2022-39978 Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. Thi… Online Pet Shop We App No fix yet Fix from $1,9502022-10-27 CRITICAL 9.8 CVE-2022-41711 Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the applica… Badaso No fix yet Fix from $2,3002022-10-25 CRITICAL 9.8 CVE-2022-36452 A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious fil… Micollab 9.6+ Fix from $2,3002022-10-25 CRITICAL 9.8 CVE-2022-39305 Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 co… Gin Vue Admin 2.5.4b+ Fix from $2,3002022-10-24 HIGH 7.2 CVE-2022-42189 Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability. Emlog No fix yet Fix from $1,9502022-10-21 HIGH 8.8 CVE-2022-42198 In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload. Simple Exam Reviewer Management System No fix yet Fix from $1,9502022-10-20 HIGH 7.2 CVE-2022-42201 Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload. Simple Exam Reviewer Management System No fix yet Fix from $1,9502022-10-20 HIGH 7.2 CVE-2022-31366 An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitr… Eve Ng No fix yet Fix from $1,9502022-10-20 MEDIUM 5.4 CVE-2022-39301 sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting … Sra Admin after 1.1.1 Fix from $1,6002022-10-19 HIGH 7.2 CVE-2022-41537 Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/pro… Online Tours \& Travels Management System No fix yet Fix from $1,9502022-10-18 HIGH 7.2 CVE-2022-41504 An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute a… Billing System No fix yet Fix from $1,9502022-10-18