Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Xiaoheifs HIGH 7.2
CVE-2026-28673

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the standard plugin…

Fix: 0.4.0+
Fix from $1,950 2026-03-18
Xiaoheifs HIGH 7.2
CVE-2026-28674

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPl…

Fix: 0.4.0+
Fix from $1,950 2026-03-18
Unclassified HIGH 7.3
CVE-2026-4220

A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the fil…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4221

A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage o…

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4201

A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of …

Mitigation only
Fix from $1,950 2026-03-16
Unclassified HIGH 7.3
CVE-2026-4191

A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Pi…

Mitigation only
Fix from $1,950 2026-03-16
Sdt Cs3b1 Firmware CRITICAL 9.8
CVE-2017-20224

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-3891EPSS 25%

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation…

Mitigation only
Fix from $2,300 2026-03-13
Unclassified HIGH 8.8
CVE-2025-13067

The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is du…

Mitigation only
Fix from $1,950 2026-03-11
Resort Reservation System HIGH 8.8
CVE-2026-3800

A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?…

No fix yet
Fix from $1,950 2026-03-09
Video Surveillance System Firmware HIGH 8.8
CVE-2026-3797

A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile o…

Mitigation only
Fix from $1,950 2026-03-09
Bytedesk HIGH 8.8
CVE-2026-3748

A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/…

Fix: 1.4.5.1+
Fix from $1,950 2026-03-08
Bytedesk HIGH 8.8
CVE-2026-3749

A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/jav…

Fix: 1.4.5.1+
Fix from $1,950 2026-03-08
Backstage Plugin Techdocs Node CRITICAL 9.8
CVE-2026-29186

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb…

Fix: 1.14.3+
Fix from $2,300 2026-03-07
Flowise CRITICAL 9.8
CVE-2026-30821EPSS 15%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId…

Fix: 3.0.13+
Fix from $2,300 2026-03-07
Unclassified HIGH 8.2
CVE-2018-25171

EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code thr…

No fix yet
Fix from $1,950 2026-03-06
Unclassified MEDIUM 6.5
CVE-2018-25162

2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executable PHP files by sending multi…

No fix yet
Fix from $1,600 2026-03-06
Natro Macro HIGH 8.0
CVE-2026-28800

Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a…

Fix: 1.1.0+
Fix from $1,950 2026-03-06
Chartbrew MEDIUM 5.4
CVE-2026-27605

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4…

Fix: 4.8.4+
Fix from $1,600 2026-03-06
Avideo HIGH 8.8
CVE-2026-28502

WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVi…

Fix: 24.0+
Fix from $1,950 2026-03-06
Chamilo Lms HIGH 8.8
CVE-2026-29041

Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability ca…

Fix: 1.11.34+
Fix from $1,950 2026-03-06
Devices Pricing Program CRITICAL 9.8
CVE-2026-21536

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Unclassified HIGH 8.1
CVE-2026-3459

The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type va…

Mitigation only
Fix from $1,950 2026-03-05
Astroid Framework CRITICAL 9.8
CVE-2026-21628

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

Fix: after 3.3.10
Fix from $2,300 2026-03-05
Seppmail CRITICAL 9.8
CVE-2026-2743

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf…

Fix: after 15.0.2.1
Fix from $2,300 2026-03-05
Unclassified HIGH 8.5
CVE-2026-28133

Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue a…

Mitigation only
Fix from $1,950 2026-03-05
Unclassified CRITICAL 9.1
CVE-2026-28114

Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell …

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.9
CVE-2026-24960

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: …

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.1
CVE-2026-23802

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI En…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.9
CVE-2025-68555

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affect…

Mitigation only
Fix from $2,300 2026-03-05