Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.2
CVE-2024-58298

Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicio…

No fix yet
Fix from $2,300 2025-12-11
Unclassified HIGH 8.6
CVE-2024-58295

ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the…

No fix yet
Fix from $1,950 2025-12-11
Real Estate Property Listing App HIGH 7.2
CVE-2025-14530

A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin…

No fix yet
Fix from $1,950 2025-12-11
Easyimages2.0 CRITICAL 9.8
CVE-2025-65474

An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary c…

Fix: after 2.8.6
Fix from $2,300 2025-12-11
Easyimages2.0 HIGH 8.8
CVE-2025-65471

An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary c…

Fix: after 2.8.6
Fix from $1,950 2025-12-11
Hfly CRITICAL 9.8
CVE-2025-14522

A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /…

Fix: after 2016-05-11
Fix from $2,300 2025-12-11
Serendipity HIGH 7.2
CVE-2024-58282

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the m…

No fix yet
Fix from $1,950 2025-12-10
Wbce Cms HIGH 8.8
CVE-2024-58283

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the E…

No fix yet
Fix from $1,950 2025-12-10
Apprain HIGH 8.8
CVE-2024-58279

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files throug…

No fix yet
Fix from $1,950 2025-12-10
Dotclear HIGH 8.8
CVE-2024-58281

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media uplo…

No fix yet
Fix from $1,950 2025-12-10
Qihang Media Web Digital Signage CRITICAL 9.8
CVE-2020-36897

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to u…

Mitigation only
Fix from $2,300 2025-12-10
Unclassified HIGH 8.8
CVE-2025-14390

The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to missing or incorrect nonce va…

Mitigation only
Fix from $1,950 2025-12-10
Pipeshub CRITICAL 9.8
CVE-2025-67506

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/…

Patch available
Fix from $2,300 2025-12-10
Coldfusion CRITICAL 9.1
CVE-2025-61808EPSS 10%

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could …

Mitigation only
Fix from $2,300 2025-12-10
Leptoncms HIGH 8.8
CVE-2025-56704

LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An auth…

No fix yet
Fix from $1,950 2025-12-09
Retro Basketball Shoes Online Store HIGH 7.2
CVE-2025-14219

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/a…

No fix yet
Fix from $1,950 2025-12-08
Verysync CRITICAL 9.8
CVE-2025-14199

A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text…

Fix: after 2.21.3
Fix from $2,300 2025-12-07
Employee Profile Management System HIGH 8.8
CVE-2025-14195

A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/a…

No fix yet
Fix from $1,950 2025-12-07
Unclassified HIGH 8.8
CVE-2025-13065EPSS 13%

The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insuff…

Mitigation only
Fix from $1,950 2025-12-06
Unclassified HIGH 8.8
CVE-2025-12966

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_d…

Mitigation only
Fix from $1,950 2025-12-06
Unclassified CRITICAL 9.8
CVE-2025-12673

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() f…

Mitigation only
Fix from $2,300 2025-12-06
Diskboss HIGH 7.5
CVE-2020-36882

Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial o…

No fix yet
Fix from $1,950 2025-12-05
Zdh Web HIGH 8.8
CVE-2025-65897

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file up…

Fix: after 5.6.17
Fix from $1,950 2025-12-05
Unclassified HIGH 8.8
CVE-2025-12181

The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function…

Mitigation only
Fix from $1,950 2025-12-05
Unclassified HIGH 8.8
CVE-2025-12153

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions …

Mitigation only
Fix from $1,950 2025-12-05
Unclassified HIGH 8.8
CVE-2025-12154

The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function i…

Mitigation only
Fix from $1,950 2025-12-05
Unclassified HIGH 8.8
CVE-2025-13066

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insuff…

Mitigation only
Fix from $1,950 2025-12-05
Unclassified HIGH 8.8
CVE-2025-13543

The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class…

Mitigation only
Fix from $1,950 2025-12-04
Romm HIGH 7.6
CVE-2025-65027

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple…

Fix: 4.4.1+
Fix from $1,950 2025-12-03
Unclassified MEDIUM 6.3
CVE-2025-13949

A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.…

Mitigation only
Fix from $1,600 2025-12-03