Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.8
CVE-2026-3535

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownl…

Mitigation only
Fix from $2,300 2026-04-08
Matcha Invoice HIGH 7.2
CVE-2026-33273

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary fi…

Fix: after 2.6.6
Fix from $1,950 2026-04-08
Churchcrm CRITICAL 9.1
CVE-2026-35573

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allo…

Fix: 6.5.3+
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.8
CVE-2026-0740EPSS 63%

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Co…

Mitigation only
Fix from $2,300 2026-04-07
Chyrp Lite HIGH 7.2
CVE-2026-35174

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows…

Fix: 2026.01+
Fix from $1,950 2026-04-06
Bravecms CRITICAL 9.8
CVE-2026-35047

Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitr…

Fix: 2.0.6+
Fix from $2,300 2026-04-06
Bravecms HIGH 8.8
CVE-2026-35164

Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found i…

Fix: 2.0.6+
Fix from $1,950 2026-04-06
Unclassified MEDIUM 6.3
CVE-2026-5670

A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move…

Mitigation only
Fix from $1,600 2026-04-06
Hardened Images MEDIUM 5.5
CVE-2026-5704

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…

No fix yet
Fix from $1,600 2026-04-06
Unclassified HIGH 8.8
CVE-2019-25673

UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload mal…

No fix yet
Fix from $1,950 2026-04-05
Hi Led Wr120 G2 Firmware CRITICAL 9.8
CVE-2026-5573

A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipul…

Mitigation only
Fix from $2,300 2026-04-05
Unclassified MEDIUM 6.3
CVE-2026-5546

A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/mode…

Mitigation only
Fix from $1,600 2026-04-05
Snews CRITICAL 9.8
CVE-2016-20052

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP execut…

Fix: after 1.7
Fix from $2,300 2026-04-04
Unclassified MEDIUM 5.3
CVE-2025-14938

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "li…

Mitigation only
Fix from $1,600 2026-04-04
Unclassified MEDIUM 6.3
CVE-2026-5472

A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unkn…

No fix yet
Fix from $1,600 2026-04-03
Biztalk360 HIGH 8.8
CVE-2025-59710

An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During th…

Fix: 11.6.3963.2611+
Fix from $1,950 2026-04-03
Unclassified HIGH 8.7
CVE-2026-34735

The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. In version 1.2.0 and prior, the quickUpload() endpoint…

Mitigation only
Fix from $1,950 2026-04-02
Sharefile Storage Zones Controller HIGH 8.8
CVE-2026-2701EPSS 57%

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Fix: 5.12.4+
Fix from $1,950 2026-04-02
Unclassified MEDIUM 6.3
CVE-2026-1879

A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of t…

Mitigation only
Fix from $1,600 2026-04-01
Unclassified HIGH 7.3
CVE-2026-5261

A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base…

Mitigation only
Fix from $1,950 2026-04-01
Video Player MEDIUM 5.3
CVE-2026-30280

An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite c…

No fix yet
Fix from $1,600 2026-03-31
Unclassified MEDIUM 6.3
CVE-2026-5181

A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file …

Mitigation only
Fix from $1,600 2026-03-31
Basercms HIGH 7.2
CVE-2025-32957

baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is …

Fix: 5.2.3+
Fix from $1,950 2026-03-31
Unclassified HIGH 7.3
CVE-2026-5001

A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is the function do_POST of the f…

Mitigation only
Fix from $1,950 2026-03-28
Bludit HIGH 8.8
CVE-2026-25099

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can …

Fix: 3.18.4+
Fix from $1,950 2026-03-27
Sharp HIGH 8.8
CVE-2026-33687

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint …

Fix: 9.20.0+
Fix from $1,950 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55267

HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont…

Mitigation only
Fix from $2,300 2026-03-26
Unclassified CRITICAL 9.8
CVE-2026-4809

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a cli…

Mitigation only
Fix from $2,300 2026-03-26
Unclassified MEDIUM 5.6
CVE-2026-4830

A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php …

Mitigation only
Fix from $1,600 2026-03-26
Tiff MEDIUM 5.3
CVE-2026-33809

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or a…

Fix: 0.38.0+
Fix from $1,600 2026-03-25