Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
File Thingie HIGH 8.8
CVE-2023-53942

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web s…

No fix yet
Fix from $1,950 2025-12-18
Xperience HIGH 8.8
CVE-2019-25229

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types…

Fix: after 12.0.29
Fix from $1,950 2025-12-18
Client Database Management System HIGH 8.8
CVE-2025-14885

A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the compon…

No fix yet
Fix from $1,950 2025-12-18
Unclassified CRITICAL 9.0
CVE-2025-66074

Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webho…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.9
CVE-2025-64374

Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors:…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified CRITICAL 9.9
CVE-2025-64231

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordp…

Mitigation only
Fix from $2,300 2025-12-18
Serendipity HIGH 8.8
CVE-2023-53933

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extensi…

No fix yet
Fix from $1,950 2025-12-17
Sitemagic Cms CRITICAL 9.8
CVE-2023-53921

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. …

Mitigation only
Fix from $2,300 2025-12-17
Tinywebgallery CRITICAL 9.8
CVE-2023-53922

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload …

Mitigation only
Fix from $2,300 2025-12-17
Ulicms HIGH 8.8
CVE-2023-53924

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar exten…

No fix yet
Fix from $1,950 2025-12-17
Churchcrm HIGH 7.2
CVE-2025-68109

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Pagekit CRITICAL 9.9
CVE-2025-67164

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c…

Mitigation only
Fix from $2,300 2025-12-17
Convertx HIGH 8.8
CVE-2025-66449

ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary f…

Fix: 0.16.0+
Fix from $1,950 2025-12-16
Perch HIGH 7.2
CVE-2023-53889

Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the asset…

No fix yet
Fix from $1,950 2025-12-15
Blackcat Cms HIGH 7.2
CVE-2023-53892

Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jq…

No fix yet
Fix from $1,950 2025-12-15
Webutler HIGH 7.2
CVE-2023-53885

Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP files with system command executi…

No fix yet
Fix from $1,950 2025-12-15
Academy Lms MEDIUM 5.4
CVE-2023-53876

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting p…

No fix yet
Fix from $1,600 2025-12-15
Coppermine Photo Gallery HIGH 8.8
CVE-2023-53868

Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through th…

No fix yet
Fix from $1,950 2025-12-15
Unclassified HIGH 8.7
CVE-2023-53869

WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the med…

No fix yet
Fix from $1,950 2025-12-15
Soosyze CRITICAL 9.8
CVE-2023-53871

Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. At…

Mitigation only
Fix from $2,300 2025-12-15
Fnt Command HIGH 8.3
CVE-2024-44599

FNT Command 13.4.0 is vulnerable to Directory Traversal.

Fix: 13.4.1+
Fix from $1,950 2025-12-15
Fnt Command HIGH 8.8
CVE-2024-44598

FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

Fix: 13.4.1+
Fix from $1,950 2025-12-15
Computer Laboratory System HIGH 7.2
CVE-2025-14642

A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. …

No fix yet
Fix from $1,950 2025-12-14
Computer Laboratory System HIGH 7.2
CVE-2025-14641

A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. Th…

No fix yet
Fix from $1,950 2025-12-14
Unclassified HIGH 8.8
CVE-2025-13094

The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_fi…

Mitigation only
Fix from $1,950 2025-12-13
Online Student Enrollment System CRITICAL 9.8
CVE-2025-14583

A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing …

Mitigation only
Fix from $2,300 2025-12-12
Online Student Enrollment System HIGH 7.2
CVE-2025-14582

A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=us…

No fix yet
Fix from $1,950 2025-12-12
Unclassified HIGH 8.8
CVE-2025-12968

The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all ver…

Mitigation only
Fix from $1,950 2025-12-12
Wbce Cms HIGH 8.8
CVE-2025-34506

WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules…

Fix: after 1.6.3
Fix from $1,950 2025-12-11
Xbtitfm HIGH 7.2
CVE-2024-58313

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execut…

No fix yet
Fix from $1,950 2025-12-11