Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.3
CVE-2012-10027

WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadi…

No fix yet
Fix from $2,300 2025-08-05
Wp Import Export Lite HIGH 8.8
CVE-2025-5061

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_…

Fix: 3.9.30+
Fix from $1,950 2025-08-05
Wp Import Export Lite HIGH 8.8
CVE-2025-6207

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_impo…

Fix: 3.9.29+
Fix from $1,950 2025-08-05
Xboot CRITICAL 9.8
CVE-2025-8526

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file x…

Fix: after 3.3.4
Fix from $2,300 2025-08-04
Zkeacms CRITICAL 9.8
CVE-2025-52239

An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.

Mitigation only
Fix from $2,300 2025-08-04
Unclassified CRITICAL 9.3
CVE-2013-10054

An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitra…

No fix yet
Fix from $2,300 2025-08-04
Unclassified MEDIUM 6.4
CVE-2025-54962

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these …

Mitigation only
Fix from $1,600 2025-08-04
Kitchen Treasure CRITICAL 9.8
CVE-2025-8504

A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userreg…

Mitigation only
Fix from $2,300 2025-08-03
Unclassified CRITICAL 9.3
CVE-2013-10055

An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The appl…

No fix yet
Fix from $2,300 2025-08-01
Openemr HIGH 8.8
CVE-2013-10044

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator creden…

Fix: after 4.1.1
Fix from $1,950 2025-08-01
Unclassified CRITICAL 9.3
CVE-2013-10047

An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary…

No fix yet
Fix from $2,300 2025-08-01
Emlog HIGH 7.2
CVE-2025-44139

Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip

No fix yet
Fix from $1,950 2025-08-01
Unclassified HIGH 8.1
CVE-2025-7443

The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulner…

Mitigation only
Fix from $1,950 2025-08-01
Unclassified CRITICAL 9.2
CVE-2014-125126

An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentic…

No fix yet
Fix from $2,300 2025-07-31
Unclassified CRITICAL 9.5
CVE-2013-10043

A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the logon.php script allows an at…

No fix yet
Fix from $2,300 2025-07-31
Unclassified CRITICAL 9.3
CVE-2013-10038

An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to p…

No fix yet
Fix from $2,300 2025-07-31
Clipbucket CRITICAL 9.8
CVE-2013-10040

ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. T…

Fix: after 2.6
Fix from $2,300 2025-07-31
Unclassified CRITICAL 9.3
CVE-2013-10034

An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated use…

No fix yet
Fix from $2,300 2025-07-31
Online Hotel Reservation System HIGH 7.2
CVE-2025-8379

A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an unknown part of the file /adm…

No fix yet
Fix from $1,950 2025-07-31
Powercms HIGH 8.0
CVE-2025-54757

Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a produc…

Fix: 4.61 / 5.31+
Fix from $1,950 2025-07-31
Unclassified HIGH 8.8
CVE-2025-7847

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() functio…

Mitigation only
Fix from $1,950 2025-07-31
Shio CRITICAL 9.8
CVE-2025-8344

A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-ap…

Fix: after 0.3.8
Fix from $2,300 2025-07-31
Unclassified HIGH 8.8
CVE-2025-8323

The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoo…

Mitigation only
Fix from $1,950 2025-07-30
Lpar2rrd HIGH 8.8
CVE-2025-54769

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing…

Fix: after 8.04
Fix from $1,950 2025-07-29
Online Ordering System CRITICAL 9.8
CVE-2025-8256

A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin…

Mitigation only
Fix from $2,300 2025-07-28
Exam Form Submission CRITICAL 9.8
CVE-2025-8255

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the…

Mitigation only
Fix from $2,300 2025-07-28
Voting System MEDIUM 6.3
CVE-2025-8174

A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

No fix yet
Fix from $1,600 2025-07-26
Document Management System MEDIUM 6.3
CVE-2025-8171

A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some unknown pr…

Mitigation only
Fix from $1,600 2025-07-25
Tableau Server HIGH 8.5
CVE-2025-52449

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) al…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-07-25
Unclassified CRITICAL 9.3
CVE-2014-125116

A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. T…

No fix yet
Fix from $2,300 2025-07-25