Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified HIGH 8.8
CVE-2026-1756

The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::f…

Mitigation only
Fix from $1,950 2026-02-04
Bolo Solo CRITICAL 9.8
CVE-2026-1813

A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp…

Fix: after 2.6.4
Fix from $2,300 2026-02-04
School Erp Pro HIGH 7.2
CVE-2020-37084

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile phot…

No fix yet
Fix from $1,950 2026-02-03
Ci4ms HIGH 8.8
CVE-2026-25510

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.28.5.0+
Fix from $1,950 2026-02-03
School Erp Pro CRITICAL 9.8
CVE-2020-37090

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upl…

Mitigation only
Fix from $2,300 2026-02-03
Victor Cms HIGH 8.8
CVE-2020-37073

Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the …

No fix yet
Fix from $1,950 2026-02-03
Open Eclass Platform MEDIUM 5.3
CVE-2026-24673

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypa…

Fix: 4.2+
Fix from $1,600 2026-02-03
Podinfo MEDIUM 6.1
CVE-2025-70849

Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoin…

Fix: after 6.9.0
Fix from $1,600 2026-02-03
Fuxa CRITICAL 9.8
CVE-2025-69981

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow…

Mitigation only
Fix from $2,300 2026-02-03
Fpdf CRITICAL 9.8
CVE-2025-65875

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a…

Mitigation only
Fix from $2,300 2026-02-03
Mediacrush CRITICAL 9.8
CVE-2025-61506

An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpo…

Fix: after 1.0.1
Fix from $2,300 2026-02-03
Open Eclass Platform HIGH 8.8
CVE-2020-37113

GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP…

No fix yet
Fix from $1,950 2026-02-03
Unclassified HIGH 8.8
CVE-2026-1730

The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin:…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified HIGH 7.2
CVE-2026-1065

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due …

Mitigation only
Fix from $1,950 2026-02-03
Im Server CRITICAL 9.8
CVE-2025-66480

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component re…

Fix: 1.4.3+
Fix from $2,300 2026-02-02
Magicinfo 9 Server HIGH 8.8
CVE-2026-25201

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects M…

Fix: 21.1090.1+
Fix from $1,950 2026-02-02
Magicinfo 9 Server CRITICAL 9.8
CVE-2026-25200

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in …

Fix: 21.1090.1+
Fix from $2,300 2026-02-02
A8004t Firmware HIGH 7.2
CVE-2026-1742

A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cg…

Mitigation only
Fix from $1,950 2026-02-02
Unclassified HIGH 8.8
CVE-2020-37023

Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming maliciou…

No fix yet
Fix from $1,950 2026-01-30
Unclassified CRITICAL 10.0
CVE-2026-24729

An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allow…

Mitigation only
Fix from $2,300 2026-01-30
Unclassified HIGH 8.8
CVE-2020-37009

MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP fil…

No fix yet
Fix from $1,950 2026-01-29
Erugo HIGH 8.8
CVE-2026-24897

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files…

Fix: after 0.2.14
Fix from $1,950 2026-01-28
Nocodb CRITICAL 9.0
CVE-2026-24769

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in Noco…

Fix: 0.301.0+
Fix from $2,300 2026-01-28
Blue CRITICAL 9.1
CVE-2025-57794

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The applica…

Fix: 8.14.9+
Fix from $2,300 2026-01-28
Blue CRITICAL 9.9
CVE-2025-57795

Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configur…

Fix: 8.14.13+
Fix from $2,300 2026-01-28
Unclassified MEDIUM 6.5
CVE-2020-36973

PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary …

No fix yet
Fix from $1,600 2026-01-28
Unclassified HIGH 7.2
CVE-2026-1400

The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali…

Mitigation only
Fix from $1,950 2026-01-28
Computer Book Store CRITICAL 9.8
CVE-2025-69559

code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.

Mitigation only
Fix from $2,300 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69565

code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.

Mitigation only
Fix from $2,300 2026-01-27
Victor Cms HIGH 8.8
CVE-2020-36942

Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload fe…

No fix yet
Fix from $1,950 2026-01-27