Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Mozart Next 100 Firmware CRITICAL 9.8
CVE-2025-63228

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_fi…

Mitigation only
Fix from $2,300 2025-11-18
Mozart Next 100 Firmware HIGH 7.2
CVE-2025-63227

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php en…

No fix yet
Fix from $1,950 2025-11-18
Richfilemanager CRITICAL 9.8
CVE-2025-63994

An arbitrary file upload vulnerability in the /php/UploadHandler.php component of RichFilemanager v2.7.6 allows attackers to execute arbitrary code v…

Mitigation only
Fix from $2,300 2025-11-18
Dzzoffice CRITICAL 9.8
CVE-2025-63695

DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

Fix: after 2.3.7
Fix from $2,300 2025-11-18
Ewio2 M Firmware HIGH 8.8
CVE-2025-41735

A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution.

Fix: 2.2.0+
Fix from $1,950 2025-11-18
Winplus CRITICAL 9.8
CVE-2025-41347

Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to uplo…

Mitigation only
Fix from $2,300 2025-11-18
Unclassified HIGH 8.8
CVE-2025-13069

The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This is…

Mitigation only
Fix from $1,950 2025-11-18
Unclassified HIGH 8.1
CVE-2025-12528

The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic fun…

Mitigation only
Fix from $1,950 2025-11-18
Unclassified HIGH 8.8
CVE-2025-12775

The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1.1.0 via the `ajax_u…

Mitigation only
Fix from $1,950 2025-11-18
Unclassified HIGH 8.1
CVE-2025-12974

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mecha…

Mitigation only
Fix from $1,950 2025-11-18
Qatraq HIGH 8.8
CVE-2025-63748

QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails…

No fix yet
Fix from $1,950 2025-11-17
Unclassified MEDIUM 6.3
CVE-2025-13249

A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTempl…

Mitigation only
Fix from $1,600 2025-11-16
Flight Booking Software HIGH 8.8
CVE-2025-13238

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/pro…

No fix yet
Fix from $1,950 2025-11-16
News365 HIGH 7.2
CVE-2025-13185

A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. …

Fix: after 7.0.3
Fix from $1,950 2025-11-14
S Cw2503c H Firmware MEDIUM 6.8
CVE-2025-55810

A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allow…

Mitigation only
Fix from $1,600 2025-11-13
Online Voting System HIGH 8.8
CVE-2025-13061

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Pe…

No fix yet
Fix from $1,950 2025-11-12
Unclassified HIGH 7.5
CVE-2025-12048

An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote c…

Mitigation only
Fix from $1,950 2025-11-12
Ofbiz HIGH 7.3
CVE-2025-59118

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommen…

Fix: 24.09.03+
Fix from $1,950 2025-11-12
Unclassified HIGH 8.8
CVE-2025-12846

The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is…

Mitigation only
Fix from $1,950 2025-11-11
Unclassified CRITICAL 9.8
CVE-2025-11170

The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import…

Mitigation only
Fix from $2,300 2025-11-11
File Manager HIGH 7.2
CVE-2025-63678

An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers wi…

No fix yet
Fix from $1,950 2025-11-10
Employee Records System CRITICAL 9.8
CVE-2021-4462

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitr…

Mitigation only
Fix from $2,300 2025-11-10
Unclassified HIGH 7.2
CVE-2025-12867

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell b…

Mitigation only
Fix from $1,950 2025-11-10
Unclassified HIGH 7.2
CVE-2025-12399

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t…

Mitigation only
Fix from $1,950 2025-11-08
Unclassified HIGH 7.2
CVE-2025-11967

The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_impor…

Mitigation only
Fix from $1,950 2025-11-08
Unclassified HIGH 8.8
CVE-2025-12161

The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creat…

Mitigation only
Fix from $1,950 2025-11-08
Online Notes Sharing Platform CRITICAL 9.8
CVE-2025-12862

A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /…

Mitigation only
Fix from $2,300 2025-11-07
Monsta Ftp CRITICAL 9.8
CVE-2025-34299EPSS 73%

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execu…

Fix: after 2.11
Fix from $2,300 2025-11-07
Unclassified CRITICAL 9.8
CVE-2025-12352

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function …

Mitigation only
Fix from $2,300 2025-11-07
Thinkdashboard MEDIUM 6.1
CVE-2025-64176

ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an attacker can upload any file…

Fix: 0.6.8+
Fix from $1,600 2025-11-06