Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.9
CVE-2026-32536

Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious File…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.9
CVE-2026-32523

Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJ…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.1
CVE-2026-32524

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This iss…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.9
CVE-2026-32482

Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: …

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.9
CVE-2026-25413

Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affec…

Mitigation only
Fix from $2,300 2026-03-25
Kiteworks HIGH 7.2
CVE-2026-23636

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an …

Fix: 9.2.1+
Fix from $1,950 2026-03-25
Phreebookserp HIGH 8.8
CVE-2019-25647

PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute ar…

No fix yet
Fix from $1,950 2026-03-24
Phreebookserp HIGH 8.8
CVE-2019-25630

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload mal…

No fix yet
Fix from $1,950 2026-03-24
River Past Cam Do HIGH 7.8
CVE-2019-25626

River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbi…

Fix: after 3.7.6
Fix from $1,950 2026-03-24
Flexhex HIGH 7.8
CVE-2019-25627

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by trigger…

No fix yet
Fix from $1,950 2026-03-24
Unclassified HIGH 8.8
CVE-2026-3533

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as we…

Mitigation only
Fix from $1,950 2026-03-24
Csweb HIGH 8.8
CVE-2025-60947

Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code exec…

Patch available
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33717

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoE…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33647

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file con…

Fix: after 26.0
Fix from $1,950 2026-03-23
Unclassified MEDIUM 6.3
CVE-2026-4586

A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 5.3
CVE-2026-1969

The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upl…

Mitigation only
Fix from $1,600 2026-03-23
Unclassified MEDIUM 6.2
CVE-2019-25616

AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized stri…

No fix yet
Fix from $1,600 2026-03-22
Unclassified HIGH 7.3
CVE-2026-4536

A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulati…

Mitigation only
Fix from $1,950 2026-03-22
Owndms HIGH 8.2
CVE-2019-25580

ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code…

Fix: after 4.7
Fix from $1,950 2026-03-21
I Doit MEDIUM 6.5
CVE-2019-25582

i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating th…

No fix yet
Fix from $1,600 2026-03-21
Unclassified MEDIUM 6.3
CVE-2026-4505

A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages…

Mitigation only
Fix from $1,600 2026-03-20
Intranet Portal HIGH 8.8
CVE-2026-32989

Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafte…

No fix yet
Fix from $1,950 2026-03-20
Terrapack Tkservercgi HIGH 8.8
CVE-2025-67260

The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow atta…

Mitigation only
Fix from $1,950 2026-03-20
Filerise HIGH 8.8
CVE-2026-33071

FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension includi…

Fix: 3.8.0+
Fix from $1,950 2026-03-20
Xerte Online Toolkits CRITICAL 9.8
CVE-2026-32985

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality t…

Fix: after 3.14.0
Fix from $2,300 2026-03-20
Admidio HIGH 8.8
CVE-2026-32756

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documen…

Fix: 5.0.7+
Fix from $1,950 2026-03-20
Unclassified HIGH 7.2
CVE-2026-27043

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/…

Mitigation only
Fix from $1,950 2026-03-19
Unclassified CRITICAL 9.1
CVE-2026-27067

Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server…

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.0
CVE-2026-27540

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead…

Mitigation only
Fix from $2,300 2026-03-19
Aapanel CRITICAL 9.8
CVE-2026-29859

An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.

Mitigation only
Fix from $2,300 2026-03-18