Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.3
CVE-2012-10064

Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-co…

No fix yet
Fix from $2,300 2026-01-16
Easydiscuss HIGH 8.8
CVE-2026-21625

User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type…

Fix: after 5.0.15
Fix from $1,950 2026-01-16
Filemanager CRITICAL 9.8
CVE-2025-14894

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME val…

Fix: 1.0.0+
Fix from $2,300 2026-01-16
Unclassified HIGH 8.8
CVE-2025-12957

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to …

Mitigation only
Fix from $1,950 2026-01-16
Police Statistics Database System CRITICAL 9.8
CVE-2026-1021

Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload a…

Fix: after 1.0.2
Fix from $2,300 2026-01-16
Websitebaker HIGH 8.8
CVE-2021-47788

WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbi…

No fix yet
Fix from $1,950 2026-01-16
Phpwcms MEDIUM 5.4
CVE-2021-47783

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attac…

No fix yet
Fix from $1,600 2026-01-16
Unclassified CRITICAL 9.3
CVE-2011-10041

Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file …

Mitigation only
Fix from $2,300 2026-01-15
Agora Project HIGH 8.8
CVE-2025-67077

File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the Uploa…

Fix: 25.10+
Fix from $1,950 2026-01-15
Agora Project CRITICAL 9.8
CVE-2025-67079

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library vi…

Fix: 25.10+
Fix from $2,300 2026-01-15
Unclassified CRITICAL 9.8
CVE-2021-47819

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code exe…

Mitigation only
Fix from $2,300 2026-01-15
Cms CRITICAL 9.8
CVE-2021-47753

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file…

Mitigation only
Fix from $2,300 2026-01-15
Patient Management System HIGH 8.8
CVE-2021-47757

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authe…

No fix yet
Fix from $1,950 2026-01-15
Patient Management System HIGH 8.8
CVE-2021-47758

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP …

No fix yet
Fix from $1,950 2026-01-15
Unclassified HIGH 8.8
CVE-2025-13062

The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to ins…

Mitigation only
Fix from $1,950 2026-01-15
E107 HIGH 7.2
CVE-2022-50939

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files thro…

No fix yet
Fix from $1,950 2026-01-13
Wbce Cms HIGH 8.8
CVE-2022-50936

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the a…

No fix yet
Fix from $1,950 2026-01-13
E107 HIGH 7.2
CVE-2022-50916

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manag…

No fix yet
Fix from $1,950 2026-01-13
Impresscms CRITICAL 9.8
CVE-2022-50912

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. A…

Mitigation only
Fix from $2,300 2026-01-13
E107 HIGH 7.2
CVE-2022-50907

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute …

No fix yet
Fix from $1,950 2026-01-13
Nanocms HIGH 8.8
CVE-2022-50898

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenti…

No fix yet
Fix from $1,950 2026-01-13
Wallpaper Admin CRITICAL 9.8
CVE-2022-50893

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload …

Mitigation only
Fix from $2,300 2026-01-13
Arubaos HIGH 7.2
CVE-2025-37175

Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating syst…

Fix: 8.10.0.21 / 8.13.1.1+
Fix from $1,950 2026-01-13
Unclassified MEDIUM 5.3
CVE-2025-62182

Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could…

Mitigation only
Fix from $1,600 2026-01-13
Hub CRITICAL 9.8
CVE-2025-65783

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to …

Mitigation only
Fix from $2,300 2026-01-13
Unclassified MEDIUM 6.6
CVE-2026-0496

SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper…

Mitigation only
Fix from $1,600 2026-01-13
Gin Vue Admin HIGH 7.2
CVE-2026-22786

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint res…

Fix: after 2.8.7
Fix from $1,950 2026-01-12
Wem HIGH 8.8
CVE-2026-22789

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validatio…

Patch available
Fix from $1,950 2026-01-12
Emlog HIGH 8.8
CVE-2026-22799

Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file upl…

Fix: 2.6.1+
Fix from $1,950 2026-01-12
Covid 19 Contact Tracing System CRITICAL 9.8
CVE-2025-66802

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into …

Mitigation only
Fix from $2,300 2026-01-12