Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.8
CVE-2025-6679

The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and incl…

Mitigation only
Fix from $2,300 2025-08-15
Litemall HIGH 8.8
CVE-2025-8965

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/…

Fix: after 1.8.0
Fix from $1,950 2025-08-14
Unclassified CRITICAL 9.0
CVE-2025-54693

Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell to a Web Server.This issue a…

Mitigation only
Fix from $2,300 2025-08-14
Unclassified CRITICAL 9.9
CVE-2025-24775

Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issu…

Mitigation only
Fix from $2,300 2025-08-14
Umbraco Cms CRITICAL 9.8
CVE-2012-10054

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes …

Fix: 4.7.1+
Fix from $2,300 2025-08-13
Unclassified HIGH 8.7
CVE-2012-10056

PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can …

No fix yet
Fix from $1,950 2025-08-13
Avalanche HIGH 7.2
CVE-2025-8297

Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to…

Fix: 6.4.8.8008+
Fix from $1,950 2025-08-12
Eblog Site HIGH 8.8
CVE-2025-8859

A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/…

No fix yet
Fix from $1,950 2025-08-11
Unclassified CRITICAL 9.3
CVE-2012-10038

Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate…

No fix yet
Fix from $2,300 2025-08-11
Microservices Platform MEDIUM 6.1
CVE-2025-8841

A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-b…

Fix: after 6.0.0
Fix from $1,600 2025-08-11
Samarium MEDIUM 6.1
CVE-2025-8798

A vulnerability was found in oitcode samarium up to 0.9.6. It has been classified as critical. Affected is an unknown function of the file /dashboard…

Fix: after 0.9.6
Fix from $1,600 2025-08-10
Electronic Signature CRITICAL 9.8
CVE-2025-8775

A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as critical. Affected by this issue is the function ex…

Fix: after 4.34
Fix from $2,300 2025-08-09
Litemall MEDIUM 5.4
CVE-2025-8764

A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upl…

Fix: after 1.8.0
Fix from $1,600 2025-08-09
Unclassified CRITICAL 9.3
CVE-2012-10049

WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate …

No fix yet
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2012-10050

CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_write.php script. The applicati…

No fix yet
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2012-10052

EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The application fails to validate f…

No fix yet
Fix from $2,300 2025-08-08
Unclassified HIGH 8.7
CVE-2012-10042

Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default cre…

No fix yet
Fix from $1,950 2025-08-08
Unclassified CRITICAL 10.0
CVE-2012-10044

MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authenticatio…

Mitigation only
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2012-10045

XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. Th…

No fix yet
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2012-10036

Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to …

No fix yet
Fix from $2,300 2025-08-08
Unclassified MEDIUM 6.4
CVE-2025-55135

In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than…

Patch available
Fix from $1,600 2025-08-07
Vedo Suite HIGH 8.2
CVE-2025-51056

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths …

No fix yet
Fix from $1,950 2025-08-06
Grav HIGH 8.1
CVE-2025-50286EPSS 9%

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direc…

No fix yet
Fix from $1,950 2025-08-06
Unclassified CRITICAL 9.8
CVE-2025-22470

CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrar…

Mitigation only
Fix from $2,300 2025-08-06
Unclassified MEDIUM 6.5
CVE-2025-52078

File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via…

Mitigation only
Fix from $1,600 2025-08-05
Unclassified CRITICAL 9.3
CVE-2014-125113

An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5…

No fix yet
Fix from $2,300 2025-08-05
Unclassified CRITICAL 10.0
CVE-2013-10066

An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) t…

Mitigation only
Fix from $2,300 2025-08-05
Unclassified CRITICAL 9.4
CVE-2013-10067

Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the …

No fix yet
Fix from $2,300 2025-08-05
Freefloat Ftp Server CRITICAL 9.8
CVE-2012-10030

FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive syste…

Mitigation only
Fix from $2,300 2025-08-05
Unclassified CRITICAL 10.0
CVE-2012-10026

The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint …

Mitigation only
Fix from $2,300 2025-08-05