Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2022-2749 A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown fun… Gym Management System No fix yet Fix from $1,9502022-08-11 CRITICAL 9.8 CVE-2022-2750 A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dash… Company Website Cms Mitigation only Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-2751 A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of t… Company Website Cms Mitigation only Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-2736 A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashbo… Company Website Cms Mitigation only Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-2740 A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the fil… Company Website Cms Mitigation only Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-2744 A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown fun… Gym Management System Mitigation only Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-2746 A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code … Simple Online Book Store System Mitigation only Fix from $2,3002022-08-11 CRITICAL 9.8 CVE-2022-35426 UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. Ucms No fix yet Fix from $2,3002022-08-10 CRITICAL 9.1 CVE-2022-36264 In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriti… Airspot 5410 Firmware after 0.3.4.1-4 Fix from $2,3002022-08-08 HIGH 8.8 CVE-2022-2356 The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, whic… User Private Files 1.1.3+ Fix from $1,9502022-08-08 HIGH 8.8 CVE-2022-2694 A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulat… Company Website Cms No fix yet Fix from $1,9502022-08-06 HIGH 8.8 CVE-2022-2678 A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This vulnerability affects unknown … Alphaware E Commerce System No fix yet Fix from $1,9502022-08-05 CRITICAL 9.8 CVE-2022-2647 A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /api/. The manipulatio… Jeecg Boot Mitigation only Fix from $2,3002022-08-04 CRITICAL 9.8 CVE-2022-34613 Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file. Mealie No fix yet Fix from $2,3002022-08-02 HIGH 8.8 CVE-2022-34154 Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPr… Enable Svg\, Webp \& Ico Upload after 1.0.1 Fix from $1,9502022-08-01 CRITICAL 9.8 CVE-2022-34496 Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature. Hiby R3 Pro Firmware after 1.7 Fix from $2,3002022-07-29 HIGH 7.2 CVE-2022-34578 Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. Open Source Point Of Sale No fix yet Fix from $1,9502022-07-28 HIGH 7.2 CVE-2022-34120EPSS 18% Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activ… Barangay Management System No fix yet Fix from $1,9502022-07-27 HIGH 8.8 CVE-2022-34549 Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to e… Sims No fix yet Fix from $1,9502022-07-27 HIGH 8.8 CVE-2022-34971 An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a craf… Feehi Cms No fix yet Fix from $1,9502022-07-27 HIGH 7.2 CVE-2022-34965 OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/admi… Open Source Social Network No fix yet Fix from $1,9502022-07-25 CRITICAL 9.8 CVE-2022-34115 DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. Dataease Patch available Fix from $2,3002022-07-22 HIGH 7.2 CVE-2022-28700 Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. Givewp 2.21.0+ Fix from $1,9502022-07-21 HIGH 7.2 CVE-2022-34024 Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pa… Barangay Management System No fix yet Fix from $1,9502022-07-19 HIGH 7.2 CVE-2022-1565EPSS 15% The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in version… Wp All Import 3.6.8+ Fix from $1,9502022-07-18 HIGH 8.8 CVE-2022-24688 An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Exec… Dsknet No fix yet Fix from $1,9502022-07-18 CRITICAL 9.8 CVE-2021-36711EPSS 16% WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. Octobot 0.4.4+ Fix from $2,3002022-07-16 CRITICAL 9.8 CVE-2022-31161EPSS 27% Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t… Roxy Wi 6.1.1.0+ Fix from $2,3002022-07-15 HIGH 8.8 CVE-2022-32119 Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.ph… School Erp Pro Mitigation only Fix from $1,9502022-07-15 HIGH 8.8 CVE-2021-36461 An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by upload… Microweber No fix yet Fix from $1,9502022-07-15