Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified HIGH 8.9
CVE-2026-73373

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not incl…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73996

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-66627

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-32474

Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-32463

Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.6
CVE-2026-28192

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2024-14046

A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/contro…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-15748

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-65640

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisit…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67678

File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

Fix unknown
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50768

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the …

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.2
CVE-2026-16137

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable uplo…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-74845

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers …

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-16098

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_han…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 8.8
CVE-2026-14498

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' paramet…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 8.7
CVE-2026-74767

Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from …

No fix yet
Fix from $4,900 2026-08-15
Unclassified HIGH 8.8
CVE-2026-18438

The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Cod…

No fix yet
Fix from $4,900 2026-08-15
Unclassified HIGH 8.8
CVE-2026-15965

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t…

No fix yet
Fix from $4,900 2026-08-15
Wyse Management Suite HIGH 7.2
CVE-2026-66271

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…

No fix yet
Fix from $4,900 2026-08-14
Wyse Management Suite HIGH 7.2
CVE-2026-66270

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-58428

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49827

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 6.8
CVE-2026-65939

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within …

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-18391

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Orde…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-15039

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users t…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.8
CVE-2026-55676

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-13457

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.7
CVE-2026-72762

n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72557

An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via …

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-24330

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un…

No fix yet
Fix from $4,000 2026-08-11