Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified MEDIUM 6.3
CVE-2026-2665

A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file Sys…

Mitigation only
Fix from $1,600 2026-02-18
Mcms HIGH 7.2
CVE-2026-2666

A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Tem…

No fix yet
Fix from $1,950 2026-02-18
Scholars Tracking System HIGH 8.8
CVE-2025-70151

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoi…

No fix yet
Fix from $1,950 2026-02-18
Datastage On Cloud Pak For Data HIGH 8.8
CVE-2025-13689

IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to u…

Fix: 5.3.1+
Fix from $1,950 2026-02-17
Unclassified CRITICAL 9.8
CVE-2026-2550

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipul…

Mitigation only
Fix from $2,300 2026-02-16
Unclassified CRITICAL 9.8
CVE-2026-1306

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJ…

Mitigation only
Fix from $2,300 2026-02-14
Unclassified CRITICAL 9.8
CVE-2026-1358

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could al…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2025-14014

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Lt…

Mitigation only
Fix from $2,300 2026-02-12
Cipace HIGH 8.8
CVE-2024-50620

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce bef…

Fix: 9.17+
Fix from $1,950 2026-02-11
GitLab HIGH 7.5
CVE-2026-1458

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under …

Fix: 18.6.6 / 18.7.4+
Fix from $1,950 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-1357EPSS 33%

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions u…

Mitigation only
Fix from $2,300 2026-02-11
Agentflow HIGH 8.8
CVE-2026-2097

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell b…

Mitigation only
Fix from $1,950 2026-02-10
My Little Forum CRITICAL 9.1
CVE-2026-25923

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application f…

Fix: 20260208.1+
Fix from $2,300 2026-02-09
Unclassified HIGH 8.8
CVE-2025-10465

Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload …

Mitigation only
Fix from $1,950 2026-02-09
Douphp HIGH 7.2
CVE-2026-2226

A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File …

Fix: after 1.9
Fix from $1,950 2026-02-09
Online Music Site HIGH 7.2
CVE-2026-2213

A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Adminis…

No fix yet
Fix from $1,950 2026-02-09
Certificate CRITICAL 9.8
CVE-2026-2183

A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This aff…

Fix: after 2017-10-16
Fix from $2,300 2026-02-08
E Commerce CRITICAL 9.8
CVE-2026-2164

A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/pr…

Mitigation only
Fix from $2,300 2026-02-08
Yshopmall HIGH 8.8
CVE-2026-2146

A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar…

Fix: after 1.9.1
Fix from $1,950 2026-02-08
Online Music Site CRITICAL 9.8
CVE-2026-2133

A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCate…

Mitigation only
Fix from $2,300 2026-02-08
Tpadmin CRITICAL 9.8
CVE-2026-2113

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/web…

Fix: after 1.3.12
Fix from $2,300 2026-02-07
Monstra Cms HIGH 8.8
CVE-2025-69906

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extens…

No fix yet
Fix from $1,950 2026-02-05
Jizhicms HIGH 8.8
CVE-2020-37117

jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbit…

No fix yet
Fix from $1,950 2026-02-05
N8n HIGH 8.8
CVE-2026-25056

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed a…

Fix: 1.118.0 / 2.4.0+
Fix from $1,950 2026-02-04
Meeting Management HIGH 8.8
CVE-2026-20098

A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary f…

Fix: 3.12.1+
Fix from $1,950 2026-02-04
Unclassified MEDIUM 6.5
CVE-2026-23704

A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on…

Mitigation only
Fix from $1,600 2026-02-04
Unclassified HIGH 8.8
CVE-2026-1756

The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::f…

Mitigation only
Fix from $1,950 2026-02-04
Bolo Solo CRITICAL 9.8
CVE-2026-1813

A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp…

Fix: after 2.6.4
Fix from $2,300 2026-02-04
School Erp Pro HIGH 7.2
CVE-2020-37084

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile phot…

No fix yet
Fix from $1,950 2026-02-03
Ci4ms HIGH 8.8
CVE-2026-25510

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.28.5.0+
Fix from $1,950 2026-02-03