Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.8
CVE-2026-72592

An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on …

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-19089

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left …

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 8.8
CVE-2026-16985

The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-19210

A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?ac…

No fix yet
Fix from $1,600 2026-08-07
Unclassified CRITICAL 9.8
CVE-2022-4995

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arb…

No fix yet
Fix from $2,300 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-71434

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upl…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-70558

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67688

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-3418

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be …

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19065

A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of t…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 10.0
CVE-2026-66665

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 7.3
CVE-2026-18969

A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the fi…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-18927

A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.2
CVE-2026-18933

The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_ca…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-6147

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functi…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-54416

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php',…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-14553

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the or…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.5
CVE-2026-65986

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability tha…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-18788

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-14175

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources all…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.2
CVE-2026-67243

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative pri…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-16548

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate …

No fix yet
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-16618

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.2
CVE-2026-61524

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated admin…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.2
CVE-2026-39931

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators wit…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16060

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, re…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16250

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-12872

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authenticatio…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.2
CVE-2026-13157

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.2
CVE-2026-13158

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type t…

No fix yet
Fix from $1,950 2026-08-01