Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.0 CVE-2022-2419EPSS 13% A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collec… Urve Web Manager No fix yet Fix from $1,9502022-07-15 HIGH 8.0 CVE-2022-2420 A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/upload… Urve Web Manager No fix yet Fix from $1,9502022-07-15 HIGH 8.0 CVE-2022-2418 A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.… Urve Web Manager No fix yet Fix from $1,9502022-07-15 CRITICAL 9.8 CVE-2022-28369 Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation o… Lvskihp Indoorunit Firmware No fix yet Fix from $2,3002022-07-14 HIGH 7.5 CVE-2022-28372 On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints provide a means of pr… Lvskihp Indoorunit Firmware No fix yet Fix from $1,9502022-07-14 HIGH 8.8 CVE-2022-32114 An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF f… Strapi No fix yet Fix from $1,9502022-07-13 HIGH 8.8 CVE-2022-30216EPSS 89% Windows Server Service Tampering Vulnerability Windows 10 No fix yet Fix from $1,9502022-07-12 HIGH 8.8 CVE-2022-2297 A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function… Clinic\'s Patient Management System No fix yet Fix from $1,9502022-07-12 CRITICAL 9.8 CVE-2022-1952EPSS 23% The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads t… Easync 1.1.16+ Fix from $2,3002022-07-11 CRITICAL 9.8 CVE-2021-29281 File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affect… Archiver 15.2+ Fix from $2,3002022-07-07 HIGH 7.2 CVE-2022-31854EPSS 32% Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel. Codoforum No fix yet Fix from $1,9502022-07-07 HIGH 8.8 CVE-2015-1784 In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica… Nextgen Gallery 2.0.77.3+ Fix from $1,9502022-07-07 MEDIUM 6.5 CVE-2015-1785 In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web applica… Nextgen Gallery 2.0.77.3+ Fix from $1,6002022-07-07 CRITICAL 9.8 CVE-2022-32413 An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file. Dice No fix yet Fix from $2,3002022-07-05 HIGH 7.2 CVE-2022-2268 The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the … Wp All Import 3.6.8+ Fix from $1,9502022-07-04 CRITICAL 9.8 CVE-2022-31943 MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. Mcms No fix yet Fix from $2,3002022-07-01 HIGH 7.2 CVE-2021-37770 Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without … Nucleus Cms No fix yet Fix from $1,9502022-06-30 CRITICAL 9.8 CVE-2022-32994EPSS 18% Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload. Halo No fix yet Fix from $2,3002022-06-27 HIGH 8.8 CVE-2022-31086 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,9502022-06-27 HIGH 8.8 CVE-2022-2212 A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the… Library Management System No fix yet Fix from $1,9502022-06-27 CRITICAL 9.8 CVE-2021-38945 IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X… Cognos Analytics 11.1.7+ Fix from $2,3002022-06-24 HIGH 7.5 CVE-2022-2102 Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response… Sepcos Control And Protection Relay Firmware 1.23.21 / 1.24.8+ Fix from $1,9502022-06-24 CRITICAL 9.8 CVE-2022-1519 LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any file type, including executab… Local Run Manager after 3.1 Fix from $2,3002022-06-24 HIGH 8.8 CVE-2013-1916EPSS 13% In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server … User Photo Patch available Fix from $1,9502022-06-24 HIGH 8.8 CVE-2022-31362EPSS 18% Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects pro… Docebo after 4.0.5 Fix from $1,9502022-06-23 CRITICAL 9.8 CVE-2021-40954 Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code. Laiketui No fix yet Fix from $2,3002022-06-23 CRITICAL 9.8 CVE-2022-31374 An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted … Sv Cpt Mc310 Firmware No fix yet Fix from $2,3002022-06-21 CRITICAL 9.8 CVE-2022-2128 Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4. Trudesk 1.2.4+ Fix from $2,3002022-06-20 HIGH 7.2 CVE-2022-1939 The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to up… Allow Svg Files 1.1+ Fix from $1,9502022-06-20 HIGH 8.8 CVE-2017-20063 A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/uplo… Elefant Cms No fix yet Fix from $1,9502022-06-20