Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Greencms CRITICAL 9.8
CVE-2025-9415

A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The man…

Fix: after 2.3.0603
Fix from $2,300 2025-08-25
Unclassified HIGH 7.5
CVE-2025-53119EPSS 12%

An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server.

Mitigation only
Fix from $1,950 2025-08-25
Lemon CRITICAL 9.8
CVE-2025-9406

A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the c…

Fix: after 1.13.0
Fix from $2,300 2025-08-25
Yifang HIGH 8.8
CVE-2025-9400

A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This ma…

Fix: after 2.0.5
Fix from $1,950 2025-08-25
Vvveb CRITICAL 9.8
CVE-2025-9397

A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipul…

Fix: after 1.0.7.2
Fix from $2,300 2025-08-24
Integrated Analytics System HIGH 8.0
CVE-2025-36174

IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be execut…

Fix: after 1.0.31.0
Fix from $1,950 2025-08-24
Digital Experience Platform CRITICAL 9.8
CVE-2025-43766

The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through …

Fix: 7.4.3.132 / 2024.Q1.14+
Fix from $2,300 2025-08-23
Tableau Server HIGH 7.3
CVE-2025-26497

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Pa…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-08-22
Tableau Server HIGH 7.3
CVE-2025-26498

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) a…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-08-22
Dootask HIGH 8.8
CVE-2025-55454

An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code vi…

No fix yet
Fix from $1,950 2025-08-22
Unclassified HIGH 7.1
CVE-2025-54460

The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File …

Mitigation only
Fix from $1,950 2025-08-21
Unclassified MEDIUM 6.3
CVE-2025-27714

An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code executio…

No fix yet
Fix from $1,600 2025-08-21
Unclassified MEDIUM 6.3
CVE-2025-24489

An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to system compromise.

No fix yet
Fix from $1,600 2025-08-21
Unopim HIGH 8.8
CVE-2025-55743

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creat…

Fix: 0.2.1+
Fix from $1,950 2025-08-21
Unclassified HIGH 8.6
CVE-2025-55383

Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any locat…

Mitigation only
Fix from $1,950 2025-08-21
Unclassified CRITICAL 9.9
CVE-2025-53251

Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a Web Server.This issue affects…

Mitigation only
Fix from $2,300 2025-08-21
Emlog CRITICAL 9.8
CVE-2025-9296

A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_a…

Fix: after 2.5.18
Fix from $2,300 2025-08-21
Mattermost Server MEDIUM 6.8
CVE-2025-49222

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remo…

Fix: 9.11.18 / 10.5.9+
Fix from $1,600 2025-08-21
Directus HIGH 7.5
CVE-2025-55746

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file upd…

Fix: 11.9.3+
Fix from $1,950 2025-08-20
Digital Experience Platform MEDIUM 6.5
CVE-2025-43750

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.…

Fix: 2024.Q1.15 / 2025.Q1.2+
Fix from $1,600 2025-08-20
Online Booking \& Scheduling Calendar HIGH 7.2
CVE-2025-54677

Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-…

Fix: 4.5.5+
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.9
CVE-2025-53213

Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping elex-reachsh…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 10.0
CVE-2025-48148EPSS 15%

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Usin…

Mitigation only
Fix from $2,300 2025-08-20
Online Tour \& Travel Management System HIGH 8.8
CVE-2025-9153

A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin…

No fix yet
Fix from $1,950 2025-08-19
Unclassified HIGH 8.2
CVE-2025-8450

Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order…

Mitigation only
Fix from $1,950 2025-08-19
Moonshine MEDIUM 5.4
CVE-2025-51489

A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when…

Fix: 3.12.5+
Fix from $1,600 2025-08-19
Unclassified MEDIUM 6.3
CVE-2025-9099

A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/…

Mitigation only
Fix from $1,600 2025-08-18
Unclassified CRITICAL 9.8
CVE-2025-7441EPSS 39%

The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs t…

Mitigation only
Fix from $2,300 2025-08-16
Unclassified HIGH 8.8
CVE-2025-6079

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ho…

Mitigation only
Fix from $1,950 2025-08-16
Unclassified CRITICAL 9.2
CVE-2025-54473

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code executio…

Mitigation only
Fix from $2,300 2025-08-15