Vulnerability index

Browse CVEs

4,181 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2022-2111 Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2. Inventree 0.7.2+ Fix from $1,9502022-06-17 HIGH 7.2 CVE-2022-32433 itsourcecode Advanced School Management System v1.0 is vulnerable to Arbitrary code execution via ip/school/view/all_teacher.php. Advanced School Management System No fix yet Fix from $1,9502022-06-15 CRITICAL 9.8 CVE-2021-40940 Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability. Monstra after 3.0.4 Fix from $2,3002022-06-15 CRITICAL 9.8 CVE-2021-42675 Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code exe… Kreasfero Mitigation only Fix from $2,3002022-06-14 MEDIUM 6.5 CVE-2022-31041 Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields c… Open Forms 1.0.9+ Fix from $1,6002022-06-13 HIGH 7.2 CVE-2022-0863EPSS 24% The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin… Wp Svg Icons after 3.2.3 Fix from $1,9502022-06-13 CRITICAL 9.8 CVE-2017-20021 A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component Fil… Solar Log 250 Firmware No fix yet Fix from $2,3002022-06-09 MEDIUM 6.7 CVE-2021-35532 A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or mal… Txpert Hub Coretec 4 Firmware Mitigation only Fix from $1,6002022-06-07 HIGH 7.2 CVE-2022-30860EPSS 24% FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel. Fudforum 3.1.2+ Fix from $1,9502022-06-06 CRITICAL 9.8 CVE-2022-32019 Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car. Car Rental Management System No fix yet Fix from $2,3002022-06-02 HIGH 8.8 CVE-2021-45982 NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. Ngeniusone Mitigation only Fix from $1,9502022-06-02 CRITICAL 9.8 CVE-2022-30808EPSS 17% elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. Elite Cms No fix yet Fix from $2,3002022-06-02 HIGH 8.8 CVE-2022-30819 In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file. Wedding Management System No fix yet Fix from $1,9502022-06-02 HIGH 8.8 CVE-2022-30820 In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file. Wedding Management System No fix yet Fix from $1,9502022-06-02 HIGH 8.8 CVE-2022-30821 In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vul… Wedding Management System No fix yet Fix from $1,9502022-06-02 HIGH 8.8 CVE-2022-30822 In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file. Wedding Management System No fix yet Fix from $1,9502022-06-02 CRITICAL 9.8 CVE-2022-30506 An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file. Mcms No fix yet Fix from $2,3002022-06-02 CRITICAL 9.8 CVE-2022-30423 Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system informa… Merchandise Online Store No fix yet Fix from $2,3002022-06-02 HIGH 8.8 CVE-2022-29725 An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file. Witycms No fix yet Fix from $1,9502022-06-02 HIGH 8.8 CVE-2022-29624 An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file. Tpcms No fix yet Fix from $1,9502022-06-02 HIGH 7.5 CVE-2022-24581 ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading… Aceweb Online Portal 3.5.065+ Fix from $1,9502022-06-02 CRITICAL 9.8 CVE-2022-24239 ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp. Aceweb Online Portal 3.5.068+ Fix from $2,3002022-06-02 CRITICAL 9.8 CVE-2021-26634 SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromis… Maxboard 1.9.6+ Fix from $2,3002022-06-02 HIGH 7.5 CVE-2021-33615 RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type. Archer 6.9.3.4 / 6.10.0.2+ Fix from $1,9502022-06-02 CRITICAL 9.8 CVE-2022-29632EPSS 17% An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code … Roncoo Education No fix yet Fix from $2,3002022-05-26 HIGH 7.8 CVE-2022-29637 An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file. Mindoc No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29651 An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code vi… Online Food Ordering System Mitigation only Fix from $1,9502022-05-25 CRITICAL 9.8 CVE-2021-42654 SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. Siteserver Cms 5.1+ Fix from $2,3002022-05-24 HIGH 7.2 CVE-2022-1837 A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=re… Home Clean Services Management System No fix yet Fix from $1,9502022-05-24 MEDIUM 5.4 CVE-2022-1811 Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. Publify 9.2.9+ Fix from $1,6002022-05-23