Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified HIGH 7.5
CVE-2026-53599

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/media…

No fix yet
Fix from $1,950 2026-07-31
Fms Employee CRITICAL 9.8
CVE-2026-21662

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec…

Fix: after 2025.3.1
Fix from $2,300 2026-07-31
Unclassified HIGH 8.8
CVE-2026-16236

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing …

Mitigation only
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-14483

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5…

Mitigation only
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-63223

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe c…

No fix yet
Fix from $2,300 2026-07-31
Unclassified HIGH 8.8
CVE-2026-67206

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-44103

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware up…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.1
CVE-2026-44097

A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in …

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via…

No fix yet
Fix from $2,300 2026-07-30
Gridbox HIGH 8.8
CVE-2026-65885

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo…

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Unclassified HIGH 8.8
CVE-2026-14270

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP we…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 7.2
CVE-2026-12476

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insuffic…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-13714

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload fun…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 8.1
CVE-2026-10818

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_…

No fix yet
Fix from $1,950 2026-07-25
Unclassified CRITICAL 9.3
CVE-2026-24727

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System …

No fix yet
Fix from $2,300 2026-07-24
Unclassified CRITICAL 9.1
CVE-2026-65461

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

Mitigation only
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65455

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-27064

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-14282

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to ar…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.4
CVE-2026-63048

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authen…

No fix yet
Fix from $2,300 2026-07-22
Unclassified MEDIUM 6.3
CVE-2026-16451

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the f…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16447

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The man…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16332

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipul…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16329

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16330

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. T…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16327

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a …

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16324

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.8
CVE-2026-53593

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous …

No fix yet
Fix from $1,950 2026-07-20