Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Migration\, Backup\, Staging HIGH 7.2
CVE-2025-5961EPSS 53%

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val…

Fix: 0.9.117+
Fix from $1,950 2025-07-03
Unclassified CRITICAL 9.8
CVE-2025-5746

The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali…

Mitigation only
Fix from $2,300 2025-07-02
Library System CRITICAL 9.8
CVE-2025-6900

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /a…

Mitigation only
Fix from $2,300 2025-06-30
Simple Company Website HIGH 7.2
CVE-2025-6873

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown proce…

No fix yet
Fix from $1,950 2025-06-29
Simple Company Website HIGH 7.2
CVE-2025-6872

A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /c…

No fix yet
Fix from $1,950 2025-06-29
Simple Forum HIGH 8.8
CVE-2025-6848

A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of th…

No fix yet
Fix from $1,950 2025-06-29
Simple Photo Gallery CRITICAL 9.8
CVE-2025-6843

A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mitigation only
Fix from $2,300 2025-06-29
Library System CRITICAL 9.8
CVE-2025-6837

A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of t…

Mitigation only
Fix from $2,300 2025-06-29
Unclassified CRITICAL 9.1
CVE-2025-53260

Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress file-manager-plugin-for-wordpress…

Mitigation only
Fix from $2,300 2025-06-27
Unclassified CRITICAL 10.0
CVE-2025-49885

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-…

Mitigation only
Fix from $2,300 2025-06-27
Fusionforge CRITICAL 9.8
CVE-2014-0468

Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploaded in the…

Fix: 5.3+
Fix from $2,300 2025-06-26
Fx2 Firmware CRITICAL 9.8
CVE-2025-30131

An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploa…

Mitigation only
Fix from $2,300 2025-06-26
Unclassified CRITICAL 10.0
CVE-2025-34046

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/i…

Mitigation only
Fix from $2,300 2025-06-26
Car Rental System HIGH 8.8
CVE-2025-6667

A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

No fix yet
Fix from $1,950 2025-06-25
Zoomsounds CRITICAL 9.1
CVE-2021-4457

The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

Fix: 6.05+
Fix from $2,300 2025-06-25
Firefox HIGH 8.1
CVE-2025-6435

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.downl…

Fix: 140.0+
Fix from $1,950 2025-06-24
Aiomatic HIGH 7.5
CVE-2025-6206

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file…

Fix: 2.5.1+
Fix from $1,950 2025-06-24
Unclassified CRITICAL 10.0
CVE-2025-34040EPSS 14%

An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters a…

Mitigation only
Fix from $2,300 2025-06-24
Ruoyi Ai CRITICAL 9.8
CVE-2025-6466

A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/u…

Fix: 2.0.1+
Fix from $2,300 2025-06-22
Online Recruitment Management System HIGH 8.8
CVE-2025-6422

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown …

No fix yet
Fix from $1,950 2025-06-21
Beaver Builder HIGH 7.2
CVE-2025-4102

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '…

Fix: 2.9.1.1+
Fix from $1,950 2025-06-20
Flir Ax8 Firmware CRITICAL 9.8
CVE-2025-6266

A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Per…

Fix: 1.49.16+
Fix from $2,300 2025-06-19
Unclassified HIGH 7.2
CVE-2025-23171

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit fil…

Mitigation only
Fix from $1,950 2025-06-19
Timetrax CRITICAL 9.9
CVE-2025-46157

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form

Mitigation only
Fix from $2,300 2025-06-18
Ultimate Addons For Contact Form 7 HIGH 7.2
CVE-2025-6220

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_opt…

Fix: 3.5.13+
Fix from $1,950 2025-06-18
Unclassified HIGH 7.2
CVE-2025-6086

The CSV Me plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'csv_me_options_page' functio…

Mitigation only
Fix from $1,950 2025-06-18
Unclassified HIGH 8.8
CVE-2025-4413

The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in…

Mitigation only
Fix from $1,950 2025-06-18
Experience Commerce HIGH 8.8
CVE-2025-34511EPSS 16%

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u…

Fix: 10.4+
Fix from $1,950 2025-06-17
Apex Central HIGH 7.5
CVE-2025-47866

An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary fil…

Mitigation only
Fix from $1,950 2025-06-17
Unclassified CRITICAL 10.0
CVE-2025-49444

Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor allows Upload a Web Shell to a W…

Mitigation only
Fix from $2,300 2025-06-17