Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Modula Image Gallery MEDIUM 6.6
CVE-2025-13646

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' fu…

Fix: 2.13.3+
Fix from $1,600 2025-12-03
Evershop HIGH 7.5
CVE-2025-65844

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint i…

No fix yet
Fix from $1,950 2025-12-02
Unclassified HIGH 8.8
CVE-2025-13827

Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media …

Mitigation only
Fix from $1,950 2025-12-02
Unclassified HIGH 8.1
CVE-2025-13516

The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and includ…

Mitigation only
Fix from $1,950 2025-12-02
Mogublog CRITICAL 9.8
CVE-2025-13815

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This man…

Fix: after 5.2
Fix from $2,300 2025-12-01
Unica MEDIUM 6.3
CVE-2025-51736

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

No fix yet
Fix from $1,600 2025-11-28
Unclassified HIGH 8.8
CVE-2025-13536

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, a…

Mitigation only
Fix from $1,950 2025-11-27
Mozart Next 3000 Firmware CRITICAL 9.8
CVE-2025-66255

Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 3…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66256

Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300…

Mitigation only
Fix from $2,300 2025-11-26
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-66250

Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified CRITICAL 9.8
CVE-2025-13597

The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all v…

Mitigation only
Fix from $2,300 2025-11-25
Unclassified CRITICAL 9.8
CVE-2025-13595

The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all…

Mitigation only
Fix from $2,300 2025-11-25
Unclassified HIGH 7.2
CVE-2025-13376

The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified CRITICAL 9.3
CVE-2023-7330

Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacke…

Mitigation only
Fix from $2,300 2025-11-24
Advanced Library Management System HIGH 8.8
CVE-2025-13573

A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_…

No fix yet
Fix from $1,950 2025-11-24
Online Bidding System HIGH 7.2
CVE-2025-13574

A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/add…

No fix yet
Fix from $1,950 2025-11-24
Travel Agency CRITICAL 9.8
CVE-2025-13544

A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the f…

Fix: after 2025-07-05
Fix from $2,300 2025-11-23
Unclassified HIGH 7.2
CVE-2025-12973

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missin…

Mitigation only
Fix from $1,950 2025-11-21
Unclassified HIGH 8.8
CVE-2025-13156

The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in…

Mitigation only
Fix from $1,950 2025-11-21
Unclassified HIGH 8.8
CVE-2025-12138

The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, a…

Mitigation only
Fix from $1,950 2025-11-21
Wsdesk CRITICAL 9.8
CVE-2025-11456

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat…

Fix: 3.3.2+
Fix from $2,300 2025-11-21
Unclassified HIGH 7.2
CVE-2025-0645

Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows A…

Mitigation only
Fix from $1,950 2025-11-20
Retro Basketball Shoes Online Store HIGH 7.2
CVE-2025-13423

A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_prod…

No fix yet
Fix from $1,950 2025-11-20
Retro Basketball Shoes Online Store CRITICAL 9.8
CVE-2025-13411

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the fil…

Mitigation only
Fix from $2,300 2025-11-19
Homarr MEDIUM 6.1
CVE-2025-64759

Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a use…

Fix: 1.43.3+
Fix from $1,600 2025-11-19
Unclassified MEDIUM 6.9
CVE-2025-34336

eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/in…

Mitigation only
Fix from $1,600 2025-11-19
Fax Server CRITICAL 9.8
CVE-2025-34328

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that ex…

Fix: after 2.6.23
Fix from $2,300 2025-11-19
Fax Server CRITICAL 9.8
CVE-2025-34329

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at Audio…

Fix: after 2.6.23
Fix from $2,300 2025-11-19
Fax Server MEDIUM 5.3
CVE-2025-34330

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that ex…

Fix: after 2.6.23
Fix from $1,600 2025-11-19
Unclassified CRITICAL 9.8
CVE-2025-12057

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally…

Mitigation only
Fix from $2,300 2025-11-19