Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Real Estate Management System HIGH 8.8
CVE-2025-9941

A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulat…

No fix yet
Fix from $1,950 2025-09-04
Make Connector HIGH 7.2
CVE-2025-6085

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' funct…

Fix: after 1.5.10
Fix from $1,950 2025-09-04
Evolved Programmable Network Manager HIGH 8.8
CVE-2025-20287

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attac…

Fix: after 8.0.0
Fix from $1,950 2025-09-03
Online Shopping Portal CRITICAL 9.1
CVE-2025-57148

phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.

No fix yet
Fix from $2,300 2025-09-03
Real Estate Management System CRITICAL 9.8
CVE-2025-9847

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This ma…

Mitigation only
Fix from $2,300 2025-09-03
Mobile Shop Management System HIGH 8.8
CVE-2025-9841

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewPro…

No fix yet
Fix from $1,950 2025-09-03
E3 Supervisory Controller Firmware MEDIUM 6.1
CVE-2025-52546

E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan fil…

Fix: 2.31f01+
Fix from $1,600 2025-09-02
Sim MEDIUM 6.1
CVE-2025-9800

A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of th…

Fix: after 0.3.40
Fix from $1,600 2025-09-01
Tianti MEDIUM 5.4
CVE-2025-9795

A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jef…

Fix: after 2.3
Fix from $1,600 2025-09-01
Remote Clinic CRITICAL 9.8
CVE-2025-9775

A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the …

Fix: after 2.0
Fix from $2,300 2025-09-01
Remote Clinic CRITICAL 9.8
CVE-2025-9772

A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argu…

Fix: after 2.0
Fix from $2,300 2025-09-01
Unclassified CRITICAL 9.9
CVE-2025-31100

Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to a Web Server.This issue affe…

Mitigation only
Fix from $2,300 2025-08-31
Unclassified HIGH 8.7
CVE-2012-10062

A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload a…

No fix yet
Fix from $1,950 2025-08-30
Unclassified CRITICAL 10.0
CVE-2009-20011

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure h…

Mitigation only
Fix from $2,300 2025-08-30
Ehrd Ctms CRITICAL 9.8
CVE-2025-54944

An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers …

Fix: 10.11+
Fix from $2,300 2025-08-30
Wegia HIGH 8.8
CVE-2025-58159

WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper…

Fix: 3.4.11+
Fix from $1,950 2025-08-29
Booster For Woocommerce CRITICAL 9.8
CVE-2024-13342

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_ord…

Fix: 7.2.5+
Fix from $2,300 2025-08-29
Unclassified CRITICAL 9.9
CVE-2025-58048

Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows …

Patch available
Fix from $2,300 2025-08-28
Unclassified MEDIUM 5.4
CVE-2025-31979

A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type res…

Mitigation only
Fix from $1,600 2025-08-28
Nagios Xi HIGH 8.8
CVE-2024-13986

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Cor…

Fix: 2024+
Fix from $1,950 2025-08-28
Unclassified CRITICAL 10.0
CVE-2025-49387

Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-…

Mitigation only
Fix from $2,300 2025-08-28
Unclassified CRITICAL 9.8
CVE-2025-54762

SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS c…

Mitigation only
Fix from $2,300 2025-08-28
Unclassified CRITICAL 9.8
CVE-2025-53970

SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS c…

Mitigation only
Fix from $2,300 2025-08-28
Unclassified MEDIUM 6.1
CVE-2024-9648

The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the WP_Ulike_Pro_File_Uploa…

Mitigation only
Fix from $1,600 2025-08-28
Unclassified CRITICAL 10.0
CVE-2025-34163

Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation a…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 10.0
CVE-2024-13981

LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerabil…

Mitigation only
Fix from $2,300 2025-08-27
Unclassified CRITICAL 10.0
CVE-2023-7309

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated M…

Mitigation only
Fix from $2,300 2025-08-27
Badaso CRITICAL 9.8
CVE-2025-52353

An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP …

Mitigation only
Fix from $2,300 2025-08-26
Human Resource Information System CRITICAL 9.8
CVE-2025-9475

A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file…

Mitigation only
Fix from $2,300 2025-08-26
Human Resource Information System CRITICAL 9.8
CVE-2025-9476

A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the f…

Mitigation only
Fix from $2,300 2025-08-26