Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Ruoyi MEDIUM 5.4
CVE-2025-7906

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi…

Fix: after 4.8.1
Fix from $1,600 2025-07-20
Identsoft HIGH 7.2
CVE-2025-7898

A vulnerability was found in Codecanyon iDentSoft 2.0. It has been classified as critical. This affects an unknown part of the file /clinica/profile/…

No fix yet
Fix from $1,950 2025-07-20
Unclassified HIGH 8.8
CVE-2025-46384

CWE-434 Unrestricted Upload of File with Dangerous Type

No fix yet
Fix from $1,950 2025-07-20
Moneyprinterturbo CRITICAL 9.8
CVE-2025-7895

A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of …

Fix: after 1.2.6
Fix from $2,300 2025-07-20
Metacrm HIGH 8.8
CVE-2025-7880

A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality o…

Fix: after 6.4.2
Fix from $1,950 2025-07-20
Metacrm CRITICAL 9.8
CVE-2025-7879

A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown func…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Metacrm HIGH 8.8
CVE-2025-7878

A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /c…

Fix: after 6.4.2
Fix from $1,950 2025-07-20
Metacrm CRITICAL 9.8
CVE-2025-7877

A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affects some unknown processin…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Jeesite MEDIUM 5.4
CVE-2025-7864

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main…

Fix: 5.12.1+
Fix from $1,600 2025-07-20
Work The Flow File Upload CRITICAL 9.8
CVE-2015-10138

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upl…

Fix: after 2.5.2
Fix from $2,300 2025-07-19
Wpshop 2 CRITICAL 9.8
CVE-2015-10135

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function…

Fix: 1.3.9.6+
Fix from $2,300 2025-07-19
Wp Mobile Detector CRITICAL 9.8
CVE-2016-15043EPSS 10%

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in version…

Fix: after 3.5
Fix from $2,300 2025-07-19
Front End Editor CRITICAL 9.8
CVE-2012-10019

The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in vers…

Fix: 2.3+
Fix from $2,300 2025-07-19
Filemanager CRITICAL 9.8
CVE-2025-46001

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via up…

Fix: after 2.0.0
Fix from $2,300 2025-07-18
Unclassified HIGH 7.5
CVE-2025-7438

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_act…

Mitigation only
Fix from $1,950 2025-07-18
Unclassified CRITICAL 9.8
CVE-2025-6222

The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary …

Mitigation only
Fix from $2,300 2025-07-18
Online Ordering System HIGH 8.8
CVE-2025-7755

A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of t…

No fix yet
Fix from $1,950 2025-07-17
Unclassified CRITICAL 9.3
CVE-2025-34121

An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post…

No fix yet
Fix from $2,300 2025-07-16
Unified Intelligence Center HIGH 8.8
CVE-2025-20274

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload ar…

Mitigation only
Fix from $1,950 2025-07-16
Unclassified CRITICAL 9.1
CVE-2025-48300

Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web Shell to a Web Server.This is…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified CRITICAL 10.0
CVE-2025-29009

Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-a…

Mitigation only
Fix from $2,300 2025-07-16
Tikiwiki Cms\/groupware CRITICAL 9.8
CVE-2025-34111

An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul…

Fix: after 15.1
Fix from $2,300 2025-07-15
Unclassified CRITICAL 9.4
CVE-2025-34104

An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnera…

Mitigation only
Fix from $2,300 2025-07-15
Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks CRITICAL 9.8
CVE-2025-7340

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads …

Fix: 2.2.2+
Fix from $2,300 2025-07-15
Kkfileviewofficeedit CRITICAL 9.8
CVE-2025-7627

A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by t…

Fix: after 2019-03-19
Fix from $2,300 2025-07-14
Online Movie Theater Seat Reservation System CRITICAL 9.8
CVE-2025-7547

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function…

Mitigation only
Fix from $2,300 2025-07-13
Sales And Inventory System CRITICAL 9.8
CVE-2025-7538

A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pa…

Mitigation only
Fix from $2,300 2025-07-13
Unclassified MEDIUM 6.3
CVE-2025-7487

A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This…

Mitigation only
Fix from $1,600 2025-07-12
Simple Car Rental System HIGH 7.2
CVE-2025-7477

A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown proc…

No fix yet
Fix from $1,950 2025-07-12
Csv Import \/ Export CRITICAL 9.8
CVE-2020-36849

The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins…

Fix: after 3.0.3
Fix from $2,300 2025-07-12