Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified MEDIUM 6.3
CVE-2026-7043

A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. T…

Mitigation only
Fix from $1,600 2026-04-26
Unclassified HIGH 8.1
CVE-2026-5364

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3.…

Mitigation only
Fix from $1,950 2026-04-24
Flowise HIGH 8.8
CVE-2026-41269

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload setti…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-6885

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated rem…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-3844EPSS 37%

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote'…

Mitigation only
Fix from $2,300 2026-04-23
Security Verify Directory HIGH 7.2
CVE-2025-36074

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not v…

Fix: after 10.0.3
Fix from $1,950 2026-04-23
Unclassified MEDIUM 6.1
CVE-2026-6835

The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any…

Mitigation only
Fix from $1,600 2026-04-22
Unclassified CRITICAL 9.3
CVE-2019-25714

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to…

Mitigation only
Fix from $2,300 2026-04-21
Visitor Management System HIGH 7.2
CVE-2026-37748

Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The …

No fix yet
Fix from $1,950 2026-04-21
Unclassified CRITICAL 9.1
CVE-2026-6257

Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file …

Patch available
Fix from $2,300 2026-04-20
Unclassified HIGH 8.8
CVE-2026-6249

Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated attackers to execute arbitrary…

Patch available
Fix from $1,950 2026-04-20
Magento HIGH 8.8
CVE-2026-40488

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Fix: 20.17.0+
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6602

A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 7.3
CVE-2026-6596

A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/b…

Mitigation only
Fix from $1,950 2026-04-20
Unclassified HIGH 8.8
CVE-2026-6518

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in al…

Mitigation only
Fix from $1,950 2026-04-18
Postiz CRITICAL 9.0
CVE-2026-40487

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitr…

Fix: 2.21.6+
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.1
CVE-2026-40484

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive…

Patch available
Fix from $2,300 2026-04-18
Unclassified HIGH 8.1
CVE-2026-5718

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and includin…

Mitigation only
Fix from $1,950 2026-04-17
Unclassified MEDIUM 6.3
CVE-2026-6489

A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of th…

Mitigation only
Fix from $1,600 2026-04-17
Unclassified HIGH 8.7
CVE-2026-40262

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies…

Patch available
Fix from $1,950 2026-04-17
Weblate HIGH 8.0
CVE-2026-33435

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which cou…

Fix: 5.17+
Fix from $1,950 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-1555

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all v…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.9
CVE-2026-38526

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute ar…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified HIGH 8.8
CVE-2026-40040

Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffecti…

Mitigation only
Fix from $1,950 2026-04-13
Pandora Fms HIGH 7.2
CVE-2026-30804

Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 …

Fix: 800.1+
Fix from $1,950 2026-04-13
Unclassified HIGH 8.4
CVE-2018-25258

RGui 3.5.0 contains a local buffer overflow vulnerability in the GUI preferences dialog that allows attackers to bypass DEP protections through struc…

No fix yet
Fix from $1,950 2026-04-12
Chamilo Lms HIGH 8.8
CVE-2026-33704

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on th…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 8.8
CVE-2026-32931

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload …

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Unclassified CRITICAL 9.8
CVE-2026-2942

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadP…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified HIGH 7.2
CVE-2026-4808

The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moveUpl…

Mitigation only
Fix from $1,950 2026-04-08