Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.1 CVE-2020-8974 In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows a… Zgr Tps200 Ng Firmware Mitigation only Fix from $2,3002022-10-17 HIGH 7.2 CVE-2022-3552EPSS 44% Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1. Boxbilling 0.0.1+ Fix from $1,9502022-10-17 CRITICAL 9.0 CVE-2022-32176 In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through th… Gin Vue Admin after 2.5.3b Fix from $2,3002022-10-17 HIGH 8.8 CVE-2022-42029 Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'… Chamilo Mitigation only Fix from $1,9502022-10-17 CRITICAL 9.8 CVE-2022-42154 An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a c… 74cmsse No fix yet Fix from $2,3002022-10-17 HIGH 7.2 CVE-2022-3549 A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unkn… Simple Cold Storage Management System Mitigation only Fix from $1,9502022-10-17 CRITICAL 9.0 CVE-2022-32177 In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through… Gin Vue Admin after 2.5.2 Fix from $2,3002022-10-14 HIGH 8.8 CVE-2022-41538 Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. … Wedding Planner No fix yet Fix from $1,9502022-10-14 HIGH 8.8 CVE-2022-41539 Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allow… Wedding Planner No fix yet Fix from $1,9502022-10-14 HIGH 7.2 CVE-2022-41533 Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProdu… Online Diagnostic Lab Management System No fix yet Fix from $1,9502022-10-13 HIGH 7.2 CVE-2022-41534 Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrd… Online Diagnostic Lab Management System No fix yet Fix from $1,9502022-10-13 CRITICAL 9.8 CVE-2022-3458 A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is a… Human Resource Management System Mitigation only Fix from $2,3002022-10-12 HIGH 7.2 CVE-2022-40921 DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php. Dedecms No fix yet Fix from $1,9502022-10-12 HIGH 7.2 CVE-2022-41406 An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary c… Church Management System No fix yet Fix from $1,9502022-10-12 HIGH 8.8 CVE-2022-40777 Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can … Email Marketer after 6.5.0 Fix from $1,9502022-10-11 CRITICAL 9.8 CVE-2022-42040EPSS 5% The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor i… D8s Algorithms No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-42043 The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the d… D8s Xml No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-42044 The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the … D8s Asns No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41380 The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the … D8s Yaml No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41381 The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is t… D8s Utility No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41382 The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the … D8s Json No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41383 The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is … D8s Archives No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41384 The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is t… D8s Domains No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41385 The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the … D8s Html No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41386 The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is t… D8s Utility No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-41387 The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the … D8s Pdfs No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-42036 The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the … D8s Urls No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-42037 The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the … D8s Asns No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-42038 The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor… D8s Ip Addresses No fix yet Fix from $2,3002022-10-11 CRITICAL 9.8 CVE-2022-42039 The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the… D8s Lists No fix yet Fix from $2,3002022-10-11