Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
School Management System CRITICAL 9.8
CVE-2025-11659

A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this vulnerability …

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11660

A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue…

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11658

A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown f…

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11657

A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This impac…

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11656

A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknow…

Mitigation only
Fix from $2,300 2025-10-13
Unclassified CRITICAL 9.8
CVE-2025-6553

The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout(…

Mitigation only
Fix from $2,300 2025-10-11
Project Center HIGH 8.8
CVE-2025-35055

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writab…

Fix: 2023.1+
Fix from $1,950 2025-10-09
Voting System CRITICAL 9.8
CVE-2025-11508

A security vulnerability has been detected in code-projects Voting System 1.0. This affects an unknown function of the file /admin/voters_add.php. Su…

Mitigation only
Fix from $2,300 2025-10-08
Hotel And Lodge Management System HIGH 7.2
CVE-2025-11470

A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function…

No fix yet
Fix from $1,950 2025-10-08
Opnform HIGH 8.8
CVE-2025-11436

A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulati…

Fix: after 1.9.3
Fix from $1,950 2025-10-08
Advanced Library Management System HIGH 8.8
CVE-2025-11426

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionali…

No fix yet
Fix from $1,950 2025-10-08
Advanced Online Voting System HIGH 8.8
CVE-2025-11417

A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unknown code of the file /admin/…

No fix yet
Fix from $1,950 2025-10-08
Hotel And Lodge Management System HIGH 8.8
CVE-2025-11398

A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unknown function of the file /prof…

No fix yet
Fix from $1,950 2025-10-07
Online Hotel Reservation System CRITICAL 9.8
CVE-2025-11354

A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Exec…

Mitigation only
Fix from $2,300 2025-10-07
Online Hotel Reservation System HIGH 8.8
CVE-2025-11353

A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of the file /admin/addgalleryexec…

No fix yet
Fix from $1,950 2025-10-07
Online Hotel Reservation System HIGH 8.8
CVE-2025-11351

A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/e…

No fix yet
Fix from $1,950 2025-10-07
Online Hotel Reservation System HIGH 8.8
CVE-2025-11352

A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown function of the file /admin/…

No fix yet
Fix from $1,950 2025-10-07
Crud Operation System CRITICAL 9.8
CVE-2025-11347

A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file a…

Fix: after 3.3
Fix from $2,300 2025-10-07
Unclassified MEDIUM 5.1
CVE-2025-61768

KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists i…

Patch available
Fix from $1,600 2025-10-06
Flowise HIGH 8.8
CVE-2025-61687EPSS 10%

Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI al…

No fix yet
Fix from $1,950 2025-10-06
Unclassified MEDIUM 6.3
CVE-2025-11320

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main…

Mitigation only
Fix from $1,600 2025-10-06
Data Leakage Prevention System CRITICAL 9.8
CVE-2025-11318

A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability af…

Mitigation only
Fix from $2,300 2025-10-06
Unclassified MEDIUM 5.4
CVE-2025-61681

KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its file upload functionality that …

Patch available
Fix from $1,600 2025-10-03
Unclassified HIGH 8.8
CVE-2025-9561

The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insufficient file validation within t…

Mitigation only
Fix from $1,950 2025-10-03
Unclassified HIGH 7.5
CVE-2025-9212

The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_uploa…

Mitigation only
Fix from $1,950 2025-10-03
Unclassified HIGH 8.6
CVE-2025-59835

LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/…

Patch available
Fix from $1,950 2025-10-02
Unclassified HIGH 8.8
CVE-2025-11221

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTON…

Mitigation only
Fix from $1,950 2025-10-02
Unclassified HIGH 8.8
CVE-2025-11020

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of…

Mitigation only
Fix from $1,950 2025-10-02
Fiora HIGH 8.8
CVE-2025-56515

File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file conten…

No fix yet
Fix from $1,950 2025-10-01
Pad Cms CRITICAL 9.8
CVE-2025-8120

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files o…

Fix: after 1.2.1
Fix from $2,300 2025-09-30