Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 10.0
CVE-2026-24815

Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangt…

Patch available
Fix from $2,300 2026-01-27
News Portal HIGH 7.2
CVE-2026-1424

A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation lea…

No fix yet
Fix from $1,950 2026-01-26
Online Examination System CRITICAL 9.8
CVE-2026-1423

A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admi…

Mitigation only
Fix from $2,300 2026-01-26
Unclassified HIGH 7.5
CVE-2026-0911

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type…

Mitigation only
Fix from $1,950 2026-01-24
Unclassified CRITICAL 9.8
CVE-2025-13374

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX a…

Mitigation only
Fix from $2,300 2026-01-24
Modern Image Gallery App CRITICAL 9.8
CVE-2025-70457

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The appli…

Mitigation only
Fix from $2,300 2026-01-23
Unclassified HIGH 8.8
CVE-2021-47904

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a m…

No fix yet
Fix from $1,950 2026-01-23
Unclassified HIGH 8.8
CVE-2021-47888

Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP …

No fix yet
Fix from $1,950 2026-01-23
Unclassified CRITICAL 10.0
CVE-2025-69828

File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.1
CVE-2025-69312

Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Upload a Web Shell to a Web …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-68986

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-68909

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious Files.This issue affects Blog…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-68910

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious Files.This issue affects Blogzee:…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-67968

Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue a…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 10.0
CVE-2025-68001

Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a Web Shell to a Web Server.Thi…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-62050

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.9
CVE-2025-62056

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <=…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified CRITICAL 10.0
CVE-2025-50002

Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects …

Mitigation only
Fix from $2,300 2026-01-22
Unclassified HIGH 8.1
CVE-2025-10856

Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This i…

Mitigation only
Fix from $1,950 2026-01-22
Meetinghub Paperless Meetings CRITICAL 9.8
CVE-2026-1331

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execu…

Fix: 2025-12-10+
Fix from $2,300 2026-01-22
Horilla MEDIUM 5.4
CVE-2026-24034

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be tr…

Fix: 1.5.0+
Fix from $1,600 2026-01-22
Horilla HIGH 8.0
CVE-2026-24010

Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Soci…

Fix: 1.5.0+
Fix from $1,950 2026-01-22
Saleor MEDIUM 5.4
CVE-2026-23499

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff …

Fix: 3.20.108 / 3.21.43+
Fix from $1,600 2026-01-21
Concert HIGH 8.8
CVE-2025-33015

IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

Fix: 2.2.0+
Fix from $1,950 2026-01-20
Unclassified HIGH 7.2
CVE-2026-1222

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upl…

Mitigation only
Fix from $1,950 2026-01-20
Aion CRITICAL 9.8
CVE-2025-55251

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code …

Mitigation only
Fix from $2,300 2026-01-19
Mpay CRITICAL 9.8
CVE-2026-1152

A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code …

Fix: after 1.2.4
Fix from $2,300 2026-01-19
Unclassified MEDIUM 6.3
CVE-2026-1126

A security vulnerability has been detected in lwj flow up to a3d2fe8133db9d3b50fda4f66f68634640344641. This affects the function uploadFile of the fi…

Mitigation only
Fix from $1,600 2026-01-18
Eyoucms CRITICAL 9.8
CVE-2026-1107

A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av…

Mitigation only
Fix from $2,300 2026-01-18
Teamwork Management System CRITICAL 9.8
CVE-2026-1061

A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/…

Fix: after 2.28.0
Fix from $2,300 2026-01-17