Total
3006 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-30266 | 1 Cltphp | 1 Cltphp | 2025-02-03 | N/A | 8.8 HIGH |
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. | |||||
CVE-2024-57761 | 2025-02-03 | N/A | 8.1 HIGH | ||
An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
CVE-2024-40513 | 2025-02-03 | N/A | 4.6 MEDIUM | ||
An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function. | |||||
CVE-2024-46210 | 2025-01-31 | N/A | 7.2 HIGH | ||
An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
CVE-2023-29721 | 1 Sofawiki Project | 1 Sofawiki | 2025-01-31 | N/A | 9.8 CRITICAL |
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution. | |||||
CVE-2023-29631 | 1 Joommasters | 1 Jms Slider | 2025-01-31 | N/A | 9.8 CRITICAL |
PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php. | |||||
CVE-2023-28409 | 1 Mw Wp Form Project | 1 Mw Wp Form | 2025-01-31 | N/A | 9.8 CRITICAL |
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file. | |||||
CVE-2023-27397 | 1 Microengine | 1 Mailform | 2025-01-31 | N/A | 9.8 CRITICAL |
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. | |||||
CVE-2023-29268 | 1 Tibco | 1 Spotfire Statistics Services | 2025-01-30 | N/A | 9.8 CRITICAL |
The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0. | |||||
CVE-2023-24269 | 1 Textpattern | 1 Textpattern | 2025-01-30 | N/A | 8.8 HIGH |
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file. | |||||
CVE-2024-13448 | 1 Themerex | 1 Addons | 2025-01-30 | N/A | 9.8 CRITICAL |
The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_data' function in all versions up to, and including, 2.32.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |||||
CVE-2023-29635 | 1 Antabot White-jotter Project | 1 Antabot White-jotter | 2025-01-30 | N/A | 9.8 CRITICAL |
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload. | |||||
CVE-2022-47878 | 1 Jedox | 1 Jedox | 2025-01-30 | N/A | 8.8 HIGH |
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. | |||||
CVE-2023-0924 | 1 Zyrex | 1 Popup | 2025-01-30 | N/A | 7.2 HIGH |
The ZYREX POPUP WordPress plugin through 1.0 does not validate the type of files uploaded when creating a popup, allowing a high privileged user (such as an Administrator) to upload arbitrary files, even when modifying the file system is disallowed, such as in a multisite install. | |||||
CVE-2023-30185 | 1 Crmeb | 1 Crmeb | 2025-01-29 | N/A | 9.8 CRITICAL |
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php. | |||||
CVE-2023-30264 | 1 Cltphp | 1 Cltphp | 2025-01-29 | N/A | 9.8 CRITICAL |
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update. | |||||
CVE-2023-30090 | 1 Sem-cms | 1 Semcms | 2025-01-29 | N/A | 9.8 CRITICAL |
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file. | |||||
CVE-2023-30122 | 1 Online Food Ordering System Project | 1 Online Food Ordering System | 2025-01-29 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |||||
CVE-2021-27280 | 1 Mblog Project | 1 Mblog | 2025-01-29 | N/A | 7.8 HIGH |
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. | |||||
CVE-2020-22755 | 1 Mingsoft | 1 Mcms | 2025-01-29 | N/A | 8.8 HIGH |
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943. |