Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified HIGH 8.4
CVE-2014-125119

A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the C…

Mitigation only
Fix from $1,950 2025-07-25
Unclassified HIGH 8.6
CVE-2016-15046

A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restri…

Mitigation only
Fix from $1,950 2025-07-25
Getsimplecms HIGH 8.8
CVE-2013-10032

An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated…

No fix yet
Fix from $1,950 2025-07-25
Droip HIGH 8.8
CVE-2025-5831

The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function…

Fix: after 2.2.0
Fix from $1,950 2025-07-25
Unclassified MEDIUM 6.3
CVE-2025-8128

A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects …

Mitigation only
Fix from $1,600 2025-07-25
Thumbnail Carousel Slider HIGH 8.8
CVE-2015-10144

The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the ima…

Fix: after 1.0.1
Fix from $1,950 2025-07-25
Unclassified CRITICAL 10.0
CVE-2025-5243

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi…

Mitigation only
Fix from $2,300 2025-07-24
Unclassified CRITICAL 9.8
CVE-2025-7852

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h…

Mitigation only
Fix from $2,300 2025-07-24
Unclassified CRITICAL 9.8
CVE-2025-7437

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form functio…

Mitigation only
Fix from $2,300 2025-07-24
Unclassified HIGH 7.5
CVE-2025-47187

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit throug…

Mitigation only
Fix from $1,950 2025-07-23
Sma 210 Firmware CRITICAL 9.1
CVE-2025-40599EPSS 10%

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative pri…

Fix: 10.2.2.1-90sv+
Fix from $2,300 2025-07-23
Pluck HIGH 7.2
CVE-2025-46099

In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the mo…

Mitigation only
Fix from $1,950 2025-07-23
Unclassified CRITICAL 9.3
CVE-2018-25114

A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing auth…

No fix yet
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54448

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54449

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server HIGH 8.8
CVE-2025-54441EPSS 8%

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $1,950 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54442

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54444

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54447

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server HIGH 8.8
CVE-2025-54439EPSS 7%

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $1,950 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54440

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Foxypress CRITICAL 9.8
CVE-2012-10020

The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions …

Fix: after 0.4.2.1
Fix from $2,300 2025-07-22
Website Contact Form With File Upload CRITICAL 9.8
CVE-2015-10137

The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up…

Fix: after 1.3.4
Fix from $2,300 2025-07-22
Jpacookieshop HIGH 8.8
CVE-2025-7939

A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of t…

No fix yet
Fix from $1,950 2025-07-21
Unclassified CRITICAL 9.4
CVE-2025-54071

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta…

Patch available
Fix from $2,300 2025-07-21
Church Donation System HIGH 7.3
CVE-2025-7931

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown function…

No fix yet
Fix from $1,950 2025-07-21
Unclassified HIGH 8.1
CVE-2025-54082

marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshm…

Patch available
Fix from $1,950 2025-07-21
Appsync MEDIUM 6.6
CVE-2025-32744

Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote a…

Fix: 4.6.0.4+
Fix from $1,600 2025-07-21
Rax30 Firmware CRITICAL 9.8
CVE-2025-44658

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensio…

Mitigation only
Fix from $2,300 2025-07-21
Unclassified HIGH 7.2
CVE-2025-7917

WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privi…

Mitigation only
Fix from $1,950 2025-07-21