Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2022-42034 Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php. Wedding Planner No fix yet Fix from $1,9502022-10-11 HIGH 8.8 CVE-2022-42229 Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php. Wedding Planner No fix yet Fix from $1,9502022-10-11 HIGH 7.5 CVE-2022-3436 A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unkno… Web Based Student Clearance System No fix yet Fix from $1,9502022-10-09 HIGH 7.2 CVE-2022-41379 An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attacker… Online Leave Management System No fix yet Fix from $1,9502022-10-07 HIGH 7.2 CVE-2022-42092 Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispu… Backdrop Cms No fix yet Fix from $1,9502022-10-07 HIGH 7.2 CVE-2022-41512 An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to … Online Diagnostic Lab Management System No fix yet Fix from $1,9502022-10-07 CRITICAL 9.8 CVE-2022-40721 Arbitrary file upload vulnerability in php uploader Creativedream File Uploader No fix yet Fix from $2,3002022-10-03 HIGH 8.8 CVE-2022-3125 The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary ex… Frontend File Manager 21.3+ Fix from $1,9502022-10-03 HIGH 7.2 CVE-2022-40886 DedeCMS 5.7.98 has a file upload vulnerability in the background. Dedecms No fix yet Fix from $1,9502022-10-03 HIGH 8.8 CVE-2022-40341 mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG f… Mojoportal Mitigation only Fix from $1,9502022-09-30 HIGH 7.2 CVE-2022-41437 Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. Billing System Project No fix yet Fix from $1,9502022-09-30 HIGH 7.2 CVE-2022-36066 Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests… Discourse 2.8.9+ Fix from $1,9502022-09-29 HIGH 8.8 CVE-2022-40407 A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file. Chamilo No fix yet Fix from $1,9502022-09-29 CRITICAL 9.8 CVE-2021-45790 An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where atta… Metersphere No fix yet Fix from $2,3002022-09-29 HIGH 7.2 CVE-2022-40048 Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function. Flatpress No fix yet Fix from $1,9502022-09-29 HIGH 8.8 CVE-2022-40878EPSS 23% In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (R… Exam Reviewer Management System No fix yet Fix from $1,9502022-09-27 CRITICAL 9.8 CVE-2022-37346 EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploitin… Product Image Bulk Upload Patch available Fix from $2,3002022-09-27 CRITICAL 9.8 CVE-2022-40050 ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1. Zfile No fix yet Fix from $2,3002022-09-26 HIGH 7.2 CVE-2022-3076 The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extensio… Cm Download Manager 2.8.6+ Fix from $1,9502022-09-26 HIGH 7.2 CVE-2022-40924 Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module i… Zoo Management System No fix yet Fix from $1,9502022-09-26 HIGH 7.2 CVE-2022-40925 Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in … Zoo Management System No fix yet Fix from $1,9502022-09-26 MEDIUM 6.5 CVE-2022-3257 Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which a… Mattermost Server 7.2.0+ Fix from $1,6002022-09-23 CRITICAL 9.8 CVE-2022-40087 Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability … Simple College Website No fix yet Fix from $2,3002022-09-22 HIGH 7.2 CVE-2022-40932 In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" mod… Zoo Management System No fix yet Fix from $1,9502022-09-22 HIGH 7.2 CVE-2022-40217 Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. Wpide after 2.6 Fix from $1,9502022-09-21 HIGH 7.2 CVE-2022-36386 Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. Wp All Import after 3.6.7 Fix from $1,9502022-09-21 MEDIUM 5.4 CVE-2022-2872 Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3. Octoprint 1.8.3+ Fix from $1,6002022-09-21 CRITICAL 9.8 CVE-2022-38916EPSS 18% A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files Pagekit No fix yet Fix from $2,3002022-09-20 CRITICAL 9.8 CVE-2022-40431 The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democrit… D8s Pdfs No fix yet Fix from $2,3002022-09-19 CRITICAL 9.8 CVE-2022-40432 The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democ… D8s Strings No fix yet Fix from $2,3002022-09-19