Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.9
CVE-2025-68562

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG…

Mitigation only
Fix from $2,300 2025-12-29
Vvvebjs CRITICAL 9.8
CVE-2024-27480

givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.

No fix yet
Fix from $2,300 2025-12-29
Vvvebjs CRITICAL 9.8
CVE-2024-25182

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

Mitigation only
Fix from $2,300 2025-12-29
College Notes Uploading System HIGH 8.8
CVE-2025-15199

A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboar…

Mitigation only
Fix from $1,950 2025-12-29
Unclassified HIGH 8.8
CVE-2025-55061

CWE-434 Unrestricted Upload of File with Dangerous Type

No fix yet
Fix from $1,950 2025-12-29
News Buzz HIGH 7.2
CVE-2025-15197

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown co…

No fix yet
Fix from $1,950 2025-12-29
Machpanel CRITICAL 9.8
CVE-2025-57460

File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.

Mitigation only
Fix from $2,300 2025-12-29
Bpmflowwebkit CRITICAL 9.8
CVE-2025-15228

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and exe…

Fix: 5.0.5+
Fix from $2,300 2025-12-29
Wmpro CRITICAL 9.8
CVE-2025-15226

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdo…

Fix: after 5.2
Fix from $2,300 2025-12-29
Smartermail CRITICAL 10.0
CVE-2025-52691 KEVEPSS 85%

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po…

Fix: 100.0.9413+
Fix from $2,300 2025-12-29
Unclassified HIGH 7.7
CVE-2025-15067

Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server.This issue affects Inno…

Mitigation only
Fix from $1,950 2025-12-29
Unclassified MEDIUM 6.3
CVE-2025-15152

A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduc…

Mitigation only
Fix from $1,600 2025-12-28
Xcms HIGH 7.2
CVE-2025-15110

A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Upload of the file Admin/Home/C…

No fix yet
Fix from $1,950 2025-12-27
Unclassified HIGH 7.3
CVE-2025-15109

A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of the file Public/javascripts/a…

Mitigation only
Fix from $1,950 2025-12-27
Unclassified HIGH 8.8
CVE-2025-2155

Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclu…

Mitigation only
Fix from $1,950 2025-12-24
Student File Management System HIGH 8.8
CVE-2025-15050

A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.p…

No fix yet
Fix from $1,950 2025-12-24
Cadmium Cms CRITICAL 9.8
CVE-2025-51511

Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.

Mitigation only
Fix from $2,300 2025-12-23
Projectsend CRITICAL 9.8
CVE-2023-53980

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Att…

Mitigation only
Fix from $2,300 2025-12-22
Webtareas HIGH 8.8
CVE-2023-53971

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functi…

No fix yet
Fix from $1,950 2025-12-22
Umbraco Cms CRITICAL 10.0
CVE-2025-67288

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this …

Mitigation only
Fix from $2,300 2025-12-22
Erpnext CRITICAL 9.6
CVE-2025-67289

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin…

No fix yet
Fix from $2,300 2025-12-22
Chestnutcms HIGH 8.8
CVE-2025-15009

A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/com…

Fix: after 1.5.8
Fix from $1,950 2025-12-22
Unclassified HIGH 8.1
CVE-2025-14800

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file…

Mitigation only
Fix from $1,950 2025-12-21
Unclassified CRITICAL 9.8
CVE-2025-13329

The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback fu…

Mitigation only
Fix from $2,300 2025-12-20
Unclassified CRITICAL 9.8
CVE-2023-53950

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions throug…

Mitigation only
Fix from $2,300 2025-12-19
Dotclear HIGH 8.8
CVE-2023-53952

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension…

No fix yet
Fix from $1,950 2025-12-19
Unclassified HIGH 8.8
CVE-2023-53956

Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the fil…

No fix yet
Fix from $1,950 2025-12-19
Turms MEDIUM 5.3
CVE-2025-66908

Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR image upload functionality. T…

No fix yet
Fix from $1,600 2025-12-19
Weblate CRITICAL 9.1
CVE-2025-68398

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i…

Fix: 5.15.1+
Fix from $2,300 2025-12-18
Webaccess\/scada CRITICAL 9.8
CVE-2025-14849

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

Mitigation only
Fix from $2,300 2025-12-18