Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.9
CVE-2025-68553

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affect…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.9
CVE-2025-68554

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarc…

Mitigation only
Fix from $2,300 2026-03-05
Freescout HIGH 8.1
CVE-2026-28289EPSS 31%

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.2…

Fix: 1.8.207+
Fix from $1,950 2026-03-03
Impact HIGH 8.0
CVE-2021-35485

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-sid…

Fix: after 19.11.2.10-20210118042150283
Fix from $1,950 2026-03-03
Unclassified HIGH 7.2
CVE-2026-2269

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Fo…

Mitigation only
Fix from $1,950 2026-03-03
Dorbycms CRITICAL 9.8
CVE-2025-14532

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which c…

Fix: after 5.0
Fix from $2,300 2026-03-02
Kiteworks HIGH 7.2
CVE-2026-28270

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files wit…

Fix: 9.2.0+
Fix from $1,950 2026-02-27
Group Office HIGH 8.8
CVE-2026-27947

Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticat…

Fix: 6.8.154 / 25.0.87+
Fix from $1,950 2026-02-27
Initiative HIGH 8.7
CVE-2026-28274

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (X…

Fix: 0.32.2+
Fix from $1,950 2026-02-26
Unclassified HIGH 8.8
CVE-2026-1565

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitra…

Mitigation only
Fix from $1,950 2026-02-26
Loris HIGH 8.8
CVE-2026-26984

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …

Fix: 26.0.5 / 27.0.2+
Fix from $1,950 2026-02-25
Asbplayer CRITICAL 9.6
CVE-2025-69771

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execut…

Fix: after 1.13.0
Fix from $2,300 2026-02-25
Sz Boot Parent CRITICAL 9.8
CVE-2026-3187

A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api…

Fix: after 0.9.0
Fix from $2,300 2026-02-25
Freescout HIGH 8.8
CVE-2026-27636

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list…

Fix: 1.8.206+
Fix from $1,950 2026-02-25
Wyse Management Suite HIGH 7.2
CVE-2026-22766

Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged at…

Fix: 5.5+
Fix from $1,950 2026-02-24
Smart Heating Integrated Management Platform CRITICAL 9.8
CVE-2026-3025

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of th…

Mitigation only
Fix from $2,300 2026-02-23
Traccar HIGH 8.7
CVE-2026-25648

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary Java…

No fix yet
Fix from $1,950 2026-02-23
Fastapiadmin HIGH 8.8
CVE-2026-2979

A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/modu…

Fix: after 2.2.0
Fix from $1,950 2026-02-23
Fastapiadmin HIGH 8.8
CVE-2026-2977

A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/m…

Fix: after 2.2.0
Fix from $1,950 2026-02-23
Fastapiadmin HIGH 8.8
CVE-2026-2978

A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api…

Fix: after 2.2.0
Fix from $1,950 2026-02-23
Fastapiadmin MEDIUM 6.5
CVE-2026-2976

A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v…

Fix: after 2.2.0
Fix from $1,600 2026-02-23
Unclassified HIGH 8.8
CVE-2018-25158

Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfind…

No fix yet
Fix from $1,950 2026-02-20
Open Source Point Of Sale HIGH 8.8
CVE-2026-26746

OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files…

No fix yet
Fix from $1,950 2026-02-20
Unclassified CRITICAL 9.9
CVE-2025-69403

Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue af…

Mitigation only
Fix from $2,300 2026-02-20
Unclassified CRITICAL 9.9
CVE-2025-68549

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affe…

Mitigation only
Fix from $2,300 2026-02-20
Music Assistant Server HIGH 8.8
CVE-2026-26975

Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow un…

Fix: 2.7.0+
Fix from $1,950 2026-02-20
Api Control Plane HIGH 7.2
CVE-2025-13590

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-1405

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified MEDIUM 5.3
CVE-2025-12500

The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versio…

Mitigation only
Fix from $1,600 2026-02-19
Electronic Archives System CRITICAL 9.8
CVE-2026-2684

A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function o…

Fix: after 3.2.210802
Fix from $2,300 2026-02-19