Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Simple Food Ordering System CRITICAL 9.8
CVE-2025-12301

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct…

Mitigation only
Fix from $2,300 2025-10-27
Learnhouse CRITICAL 9.8
CVE-2025-12268

A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/cour…

Fix: after 2025-09-21
Fix from $2,300 2025-10-27
Flight Booking Software HIGH 8.8
CVE-2025-12223

A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the co…

Fix: after 3.1
Fix from $1,950 2025-10-27
Flight Booking Software HIGH 8.8
CVE-2025-12222

A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the f…

Fix: after 3.1
Fix from $1,950 2025-10-27
User Management Php Mysql HIGH 7.2
CVE-2025-12201

A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This affects an unknown part…

Fix: after 2023-03-16
Fix from $1,950 2025-10-27
Perfreeblog HIGH 7.6
CVE-2025-60731

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

Mitigation only
Fix from $1,950 2025-10-24
Perfreeblog HIGH 7.6
CVE-2025-60735

PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function

Mitigation only
Fix from $1,950 2025-10-24
Unclassified HIGH 7.2
CVE-2025-11889

The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the im…

Mitigation only
Fix from $1,950 2025-10-24
Unclassified CRITICAL 9.8
CVE-2025-6440EPSS 31%

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrar…

Mitigation only
Fix from $2,300 2025-10-24
Unclassified CRITICAL 10.0
CVE-2025-58963

Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a Web Server.This issue affects …

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 9.1
CVE-2025-52758

Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicious Files.This issue affects Z…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 10.0
CVE-2025-49060

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue af…

Mitigation only
Fix from $2,300 2025-10-22
Unclassified CRITICAL 10.0
CVE-2025-48106

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clano…

Mitigation only
Fix from $2,300 2025-10-22
Smart School HIGH 7.2
CVE-2025-60500

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in th…

No fix yet
Fix from $1,950 2025-10-21
Daicuo MEDIUM 6.5
CVE-2025-61181

daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.

No fix yet
Fix from $1,600 2025-10-21
Tastyigniter HIGH 8.8
CVE-2025-61417

Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious…

No fix yet
Fix from $1,950 2025-10-20
Unclassified CRITICAL 9.3
CVE-2025-31342

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum…

Mitigation only
Fix from $2,300 2025-10-20
Unclassified CRITICAL 9.8
CVE-2025-11948

Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to up…

Mitigation only
Fix from $2,300 2025-10-20
Unclassified CRITICAL 9.8
CVE-2025-11391

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid…

Mitigation only
Fix from $2,300 2025-10-18
Signinghub CRITICAL 9.8
CVE-2025-56218

An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Fix: after 8.6.8
Fix from $2,300 2025-10-17
Streamax Crocus HIGH 8.8
CVE-2025-11908

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the fil…

No fix yet
Fix from $1,950 2025-10-17
Unclassified CRITICAL 9.8
CVE-2023-28814

Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to b…

Mitigation only
Fix from $2,300 2025-10-17
Unclassified HIGH 7.2
CVE-2025-10754

The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functio…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified CRITICAL 9.8
CVE-2025-10041

The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db(…

Mitigation only
Fix from $2,300 2025-10-15
Unclassified HIGH 7.2
CVE-2025-10051

The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and inclu…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified CRITICAL 9.2
CVE-2023-7305

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or …

Mitigation only
Fix from $2,300 2025-10-15
Unclassified HIGH 8.6
CVE-2025-61678EPSS 50%

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions pr…

Mitigation only
Fix from $1,950 2025-10-14
Arubaos HIGH 7.2
CVE-2025-37132

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor oper…

Fix: 8.10.0.19 / 8.12.0.6+
Fix from $1,950 2025-10-14
Unclassified CRITICAL 9.0
CVE-2025-42910

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files.…

Mitigation only
Fix from $2,300 2025-10-14
Unclassified HIGH 7.2
CVE-2025-11675

Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute w…

Mitigation only
Fix from $1,950 2025-10-13