Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 10.0
CVE-2025-6327

Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a …

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.9
CVE-2025-62065

Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.9
CVE-2025-62047

Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects Case Addons: from n/a through…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.9
CVE-2025-62016

Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0.

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 10.0
CVE-2025-60207

Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce user-registration-plugin-for-…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 10.0
CVE-2025-60235

Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium) support-ticket-system-for-wo…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.1
CVE-2025-58996

Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web …

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 10.0
CVE-2025-53283

Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-c…

Mitigation only
Fix from $2,300 2025-11-06
Api Control Plane HIGH 7.2
CVE-2025-10907

An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP ad…

Mitigation only
Fix from $1,950 2025-11-05
Unified Contact Center Express HIGH 7.2
CVE-2025-20375

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulne…

Fix: 12.5+
Fix from $1,950 2025-11-05
Unified Contact Center Express HIGH 7.2
CVE-2025-20376

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulne…

Fix: 12.5+
Fix from $1,950 2025-11-05
Unified Contact Center Express CRITICAL 9.8
CVE-2025-20354

A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arb…

Fix: 12.5+
Fix from $2,300 2025-11-05
Snipe It CRITICAL 9.9
CVE-2025-63601

Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file …

Fix: 8.3.3+
Fix from $2,300 2025-11-05
Api Control Plane HIGH 7.2
CVE-2025-3125

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpo…

Mitigation only
Fix from $1,950 2025-11-05
Unclassified CRITICAL 9.8
CVE-2025-12674

The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in …

Mitigation only
Fix from $2,300 2025-11-05
Unclassified CRITICAL 9.8
CVE-2025-12682

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in …

Mitigation only
Fix from $2,300 2025-11-04
Unclassified HIGH 8.8
CVE-2025-11724

The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all versions up to, and including…

Mitigation only
Fix from $1,950 2025-11-04
Unclassified HIGH 8.3
CVE-2025-48396

Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in…

Mitigation only
Fix from $1,950 2025-11-03
Simple Online Hotel Reservation System HIGH 7.2
CVE-2025-12593

A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /…

No fix yet
Fix from $1,950 2025-11-02
Unclassified HIGH 8.8
CVE-2025-11755

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when imp…

Mitigation only
Fix from $1,950 2025-11-01
Unclassified HIGH 8.8
CVE-2025-12171

The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image(…

Mitigation only
Fix from $1,950 2025-11-01
Unclassified CRITICAL 9.8
CVE-2025-11499

The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to…

Mitigation only
Fix from $2,300 2025-11-01
Elog HIGH 8.0
CVE-2025-62618

ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file.…

Fix: 3.1.5-20251014+
Fix from $1,950 2025-10-31
Nagios Xi HIGH 8.8
CVE-2020-36863

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler di…

Fix: 5.7.2+
Fix from $1,950 2025-10-30
Dotnetnuke CRITICAL 9.8
CVE-2025-64095EPSS 45%

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito…

Fix: 10.1.1+
Fix from $2,300 2025-10-28
Simple Food Ordering System CRITICAL 9.8
CVE-2025-12378

A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addprod…

Mitigation only
Fix from $2,300 2025-10-28
Maxsite Cms HIGH 8.8
CVE-2025-12347

A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files…

Fix: after 109
Fix from $1,950 2025-10-28
Maxsite Cms HIGH 8.8
CVE-2025-12346

A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_pos…

Fix: after 109
Fix from $1,950 2025-10-28
Unclassified MEDIUM 6.3
CVE-2025-12344

A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet …

Mitigation only
Fix from $1,600 2025-10-28
Willow Cms HIGH 7.2
CVE-2025-12331

A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unr…

Fix: after 1.4.0
Fix from $1,950 2025-10-27