Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Pad Cms CRITICAL 9.8
CVE-2025-7063

Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of…

Fix: after 1.2.1
Fix from $2,300 2025-09-30
Pad Cms CRITICAL 9.8
CVE-2025-7065

Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files o…

Fix: after 1.2.1
Fix from $2,300 2025-09-30
Unclassified MEDIUM 6.4
CVE-2025-10000

The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the…

Mitigation only
Fix from $1,600 2025-09-30
Virtual Appliance Application CRITICAL 9.1
CVE-2025-34222

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployment…

Fix: 20.0.2786 / 22.0.1049+
Fix from $2,300 2025-09-29
Enterprise Health CRITICAL 9.9
CVE-2025-35032

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how fi…

Mitigation only
Fix from $2,300 2025-09-29
Yifang HIGH 7.2
CVE-2025-11136

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the comp…

Fix: after 2.0.2
Fix from $1,950 2025-09-29
Online Tours And Travels HIGH 7.2
CVE-2025-11103

A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality …

No fix yet
Fix from $1,950 2025-09-28
Open Source Job Portal HIGH 8.8
CVE-2025-11078

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /ad…

No fix yet
Fix from $1,950 2025-09-27
Unclassified HIGH 8.6
CVE-2025-10544

Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator us…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified CRITICAL 10.0
CVE-2025-60219

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a We…

Mitigation only
Fix from $2,300 2025-09-26
Enterprise Integrator HIGH 7.2
CVE-2025-1862

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SO…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 7.2
CVE-2025-10747

The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file …

Mitigation only
Fix from $1,950 2025-09-26
Horilla MEDIUM 6.1
CVE-2025-59525

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allow…

Fix: 1.4.0+
Fix from $1,600 2025-09-24
Horilla MEDIUM 6.1
CVE-2025-59524

Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in t…

Fix: 1.4.0+
Fix from $1,600 2025-09-24
Unclassified CRITICAL 10.0
CVE-2025-9846

Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command In…

Mitigation only
Fix from $2,300 2025-09-23
Unclassified CRITICAL 9.8
CVE-2025-10412

The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to arbitrary file uploads d…

Mitigation only
Fix from $2,300 2025-09-23
Unclassified CRITICAL 9.8
CVE-2025-10147

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_origin…

Mitigation only
Fix from $2,300 2025-09-23
Unclassified HIGH 8.6
CVE-2025-10009

Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute a…

Patch available
Fix from $1,950 2025-09-22
Unclassified MEDIUM 6.3
CVE-2025-10763

A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by this issue is some unknown func…

Mitigation only
Fix from $1,600 2025-09-21
Unclassified MEDIUM 6.3
CVE-2025-10755

A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component Content-Type Handler. The ma…

Mitigation only
Fix from $1,600 2025-09-20
Unclassified MEDIUM 6.3
CVE-2025-10741

A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile …

Mitigation only
Fix from $1,600 2025-09-20
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34195

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments)…

Fix: 1.0.735 / 20.0.1330+
Fix from $2,300 2025-09-19
Unclassified HIGH 8.8
CVE-2025-10647

The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_downlo…

Mitigation only
Fix from $1,950 2025-09-19
Clipbucket HIGH 7.3
CVE-2025-55912

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload …

Fix: after 5.5.0
Fix from $1,950 2025-09-18
Unclassified MEDIUM 6.3
CVE-2025-10669

A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Per…

Mitigation only
Fix from $1,600 2025-09-18
Unclassified MEDIUM 5.3
CVE-2025-40678

Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability allows an attacker to upload …

Mitigation only
Fix from $1,600 2025-09-18
E Commerce Website HIGH 8.8
CVE-2025-10616

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipul…

No fix yet
Fix from $1,950 2025-09-17
E Commerce Website HIGH 8.8
CVE-2025-10615

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipula…

No fix yet
Fix from $1,950 2025-09-17
Online Exam Form Submission CRITICAL 9.8
CVE-2025-10600

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulatio…

Mitigation only
Fix from $2,300 2025-09-17
Unclassified HIGH 8.8
CVE-2025-9216

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbit…

Mitigation only
Fix from $1,950 2025-09-17