Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Iris HIGH 8.1
CVE-2026-22783

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS dat…

Fix: 2.4.24+
Fix from $1,950 2026-01-12
Director HIGH 8.8
CVE-2025-46068

An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism

Mitigation only
Fix from $1,950 2026-01-12
Operation And Maintenance Security Management System CRITICAL 9.8
CVE-2025-15503

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o…

Fix: after 3.0.8
Fix from $2,300 2026-01-10
Simple Php Cms HIGH 7.2
CVE-2025-15495

A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the…

No fix yet
Fix from $1,950 2026-01-09
Qloapps CRITICAL 9.8
CVE-2025-67325

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote …

Fix: after 1.7.0
Fix from $2,300 2026-01-08
Openeclass HIGH 7.2
CVE-2026-22241

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an arbitrary file upload vuln…

Fix: 4.1+
Fix from $1,950 2026-01-08
Unclassified CRITICAL 9.9
CVE-2025-67924

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affe…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.1
CVE-2025-67910

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified CRITICAL 9.8
CVE-2019-25296

The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_uploa…

Mitigation only
Fix from $2,300 2026-01-08
N8n CRITICAL 9.9
CVE-2026-21877EPSS 5%

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us…

Fix: 1.121.3+
Fix from $2,300 2026-01-08
Aris MEDIUM 6.8
CVE-2025-66837

A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

Fix: after 10.0.23.0.3587512
Fix from $1,600 2026-01-07
House Rental And Property Listing Project CRITICAL 9.8
CVE-2026-0643

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=re…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified HIGH 8.8
CVE-2025-15158

The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in the 'wpse_file_and_ext_webp' …

Mitigation only
Fix from $1,950 2026-01-07
Unclassified MEDIUM 6.1
CVE-2025-14842

The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all ve…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified CRITICAL 9.9
CVE-2025-30996

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Fol…

Mitigation only
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.1
CVE-2023-50897

Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media F…

Mitigation only
Fix from $2,300 2026-01-05
Unclassified CRITICAL 9.9
CVE-2025-31048

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: fr…

Mitigation only
Fix from $2,300 2026-01-05
Qoca Aim HIGH 8.8
CVE-2025-15240

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers t…

Fix: 2.7.6+
Fix from $1,950 2026-01-05
Javamall CRITICAL 9.8
CVE-2025-15448

A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the function Upload of the file src/m…

Mitigation only
Fix from $2,300 2026-01-05
Online Product Reservation System CRITICAL 9.8
CVE-2026-0577

A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2026-01-04
Content Management System CRITICAL 9.8
CVE-2026-0566

A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_po…

Mitigation only
Fix from $2,300 2026-01-02
Online Course Registration HIGH 8.8
CVE-2026-0547

A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-stud…

Fix: after 3.1
Fix from $1,950 2026-01-02
Unclassified HIGH 7.3
CVE-2025-15426

A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/webuploader/0.1.5/server/previe…

No fix yet
Fix from $1,950 2026-01-02
Empirecms HIGH 8.8
CVE-2025-15423

A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Suc…

Fix: after 8.0
Fix from $1,950 2026-01-02
Wangmarket MEDIUM 5.4
CVE-2025-15415

A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the…

Fix: after 6.4
Fix from $1,600 2026-01-01
School File Management System HIGH 8.8
CVE-2025-15404

A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /s…

No fix yet
Fix from $1,950 2026-01-01
Arcgis Server MEDIUM 5.6
CVE-2025-67706

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker …

Fix: after 11.5
Fix from $1,600 2025-12-31
Arcgis Server MEDIUM 5.6
CVE-2025-67707

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker …

Fix: after 11.5
Fix from $1,600 2025-12-31
Newbee Mall Plus HIGH 7.2
CVE-2025-15360

A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/commo…

No fix yet
Fix from $1,950 2025-12-30
Simple Php Cms HIGH 7.2
CVE-2025-15262

A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component S…

No fix yet
Fix from $1,950 2025-12-30