Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Sms HIGH 8.8
CVE-2025-56263

by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload…

No fix yet
Fix from $1,950 2025-09-16
Computer Laboratory System HIGH 7.3
CVE-2025-56295

code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when m…

No fix yet
Fix from $1,950 2025-09-16
Unclassified CRITICAL 9.3
CVE-2009-20006

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The int…

No fix yet
Fix from $2,300 2025-09-16
Online Student File Management System CRITICAL 9.8
CVE-2025-10480

A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.p…

Mitigation only
Fix from $2,300 2025-09-15
Unclassified MEDIUM 6.5
CVE-2025-57176

On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 al…

Mitigation only
Fix from $1,600 2025-09-15
Online Job Finder System CRITICAL 9.8
CVE-2025-10447

A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of the file /eris/applicationform…

Mitigation only
Fix from $2,300 2025-09-15
Pet Grooming Management Software HIGH 8.8
CVE-2025-10428

A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin…

No fix yet
Fix from $1,950 2025-09-15
Pet Grooming Management Software HIGH 8.8
CVE-2025-10427

A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function of the file /admin/operation/…

No fix yet
Fix from $1,950 2025-09-15
Online Student Project Report Submission And Evaluation System CRITICAL 9.8
CVE-2025-10425

A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown…

Mitigation only
Fix from $2,300 2025-09-15
Online Student Project Report Submission And Evaluation System CRITICAL 9.8
CVE-2025-10424

A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown…

Mitigation only
Fix from $2,300 2025-09-15
Smart Park Management System HIGH 8.8
CVE-2025-10398

A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects unknown code of the file FileUp…

No fix yet
Fix from $1,950 2025-09-14
Unclassified HIGH 7.3
CVE-2025-10371

A security flaw has been discovered in eCharge Hardy Barth Salia PLCC up to 2.3.81. This issue affects some unknown processing of the file /api.php. …

No fix yet
Fix from $1,950 2025-09-13
Universal Traffic Recorder Firmware HIGH 7.5
CVE-2025-45586

An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a crafted PUT request.

No fix yet
Fix from $1,950 2025-09-12
Sueamcms CRITICAL 9.8
CVE-2025-55835

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

Mitigation only
Fix from $2,300 2025-09-12
Tourism Management System HIGH 7.2
CVE-2025-57642

A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, lea…

No fix yet
Fix from $1,950 2025-09-10
Unclassified HIGH 7.2
CVE-2025-10049

The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMedia…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 7.2
CVE-2025-10001

The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i…

Mitigation only
Fix from $1,950 2025-09-10
Endpoint Manager HIGH 8.8
CVE-2025-9712EPSS 21%

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve …

Fix: 2022+
Fix from $1,950 2025-09-09
Endpoint Manager HIGH 8.8
CVE-2025-9872EPSS 14%

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve …

Fix: 2022+
Fix from $1,950 2025-09-09
Unclassified HIGH 7.3
CVE-2025-10116

A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manip…

Mitigation only
Fix from $1,950 2025-09-09
Wegia HIGH 8.8
CVE-2025-58745

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. T…

Fix: 3.4.11+
Fix from $1,950 2025-09-08
Unclassified HIGH 8.8
CVE-2025-9112

The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' fun…

Mitigation only
Fix from $1,950 2025-09-08
Unclassified CRITICAL 9.8
CVE-2025-9113

The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_medi…

Mitigation only
Fix from $2,300 2025-09-08
N8n HIGH 8.8
CVE-2025-56265

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary cod…

No fix yet
Fix from $1,950 2025-09-08
Pet Grooming Management Software HIGH 8.8
CVE-2025-10085

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manag…

No fix yet
Fix from $1,950 2025-09-08
Pet Grooming Management Software HIGH 8.8
CVE-2025-10083

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the fi…

No fix yet
Fix from $1,950 2025-09-08
Pet Grooming Management Software HIGH 7.2
CVE-2025-10081

A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation…

No fix yet
Fix from $1,950 2025-09-08
Unclassified HIGH 7.2
CVE-2025-9515

The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in …

Patch available
Fix from $1,950 2025-09-06
Unclassified CRITICAL 9.1
CVE-2025-58819

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web…

Mitigation only
Fix from $2,300 2025-09-05
Real Estate Management System HIGH 8.8
CVE-2025-9942

A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The m…

No fix yet
Fix from $1,950 2025-09-04