Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Sales And Inventory System CRITICAL 9.8
CVE-2025-7470

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the fil…

Mitigation only
Fix from $2,300 2025-07-12
Simple File List CRITICAL 9.8
CVE-2020-36847EPSS 18%

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function whic…

Fix: 4.2.3+
Fix from $2,300 2025-07-12
Unclassified HIGH 8.8
CVE-2025-6423

The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_uploa…

Mitigation only
Fix from $1,950 2025-07-12
Wpbookit CRITICAL 9.8
CVE-2025-6058EPSS 6%

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h…

Fix: 1.0.5+
Fix from $2,300 2025-07-12
Wpbookit HIGH 8.8
CVE-2025-6057

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function i…

Fix: 1.0.5+
Fix from $1,950 2025-07-12
Library System HIGH 8.8
CVE-2025-7412

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of…

No fix yet
Fix from $1,950 2025-07-10
Library System HIGH 8.8
CVE-2025-7413

A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/pro…

No fix yet
Fix from $1,950 2025-07-10
Unclassified HIGH 8.6
CVE-2025-34097

An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An att…

No fix yet
Fix from $1,950 2025-07-10
Unclassified CRITICAL 9.3
CVE-2025-34100

An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuer…

No fix yet
Fix from $2,300 2025-07-10
Analytics Content Hub CRITICAL 9.8
CVE-2024-39752

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore …

Fix: 2.4+
Fix from $2,300 2025-07-10
Library Management System HIGH 8.8
CVE-2025-7210

A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknow…

No fix yet
Fix from $1,950 2025-07-09
Unclassified CRITICAL 10.0
CVE-2025-34077EPSS 10%

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arb…

Mitigation only
Fix from $2,300 2025-07-09
Library Management System HIGH 8.8
CVE-2025-7190

A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file…

No fix yet
Fix from $1,950 2025-07-08
Juju HIGH 8.8
CVE-2025-0928

In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c…

Fix: 2.9.52 / 3.6.8+
Fix from $1,950 2025-07-08
Staff Audit System CRITICAL 9.8
CVE-2025-7181

A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /te…

Mitigation only
Fix from $2,300 2025-07-08
E Commerce Site HIGH 7.2
CVE-2025-7175

A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admi…

No fix yet
Fix from $1,950 2025-07-08
Advanced Online Voting System HIGH 8.8
CVE-2025-7152

A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unknown function of the file /ad…

No fix yet
Fix from $1,950 2025-07-08
Advanced Online Voting System HIGH 8.8
CVE-2025-7151

A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affects some unknown processing o…

No fix yet
Fix from $1,950 2025-07-07
Qconvergeconsole CRITICAL 9.8
CVE-2025-6802

Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e…

Fix: after 5.5.0.85
Fix from $2,300 2025-07-07
Online Note Sharing HIGH 8.8
CVE-2025-7124

A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown function of the file /dashboar…

No fix yet
Fix from $1,950 2025-07-07
Sim HIGH 7.5
CVE-2025-7114

A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulne…

Fix: after 0.2.1
Fix from $1,950 2025-07-07
Boyuncms CRITICAL 9.8
CVE-2025-7100

A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /appl…

Fix: after 1.4.20
Fix from $2,300 2025-07-07
Blackvue Dr590x Firmware HIGH 8.8
CVE-2025-7075

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown fun…

Fix: after 2025-06-24
Fix from $1,950 2025-07-06
Unclassified CRITICAL 10.0
CVE-2025-49414

Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Using Malicious Files.This issue affects FW…

Mitigation only
Fix from $2,300 2025-07-04
Unclassified CRITICAL 10.0
CVE-2025-30933

Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a Web Shell to a Web Server.Th…

Mitigation only
Fix from $2,300 2025-07-04
Unclassified CRITICAL 9.1
CVE-2025-28951

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web…

Mitigation only
Fix from $2,300 2025-07-04
Download Plugin HIGH 7.2
CVE-2025-6586

The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall f…

Fix: 2.2.9+
Fix from $1,950 2025-07-04
Vikrentcar HIGH 7.2
CVE-2025-5322

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the d…

Fix: 1.4.4+
Fix from $1,950 2025-07-03
Bolt HIGH 8.8
CVE-2025-34086

Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A …

Fix: after 3.7.0
Fix from $1,950 2025-07-03
Unclassified CRITICAL 9.1
CVE-2025-23968

Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server…

Mitigation only
Fix from $2,300 2025-07-03