Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Flir Ax8 Firmware CRITICAL 9.8
CVE-2025-6266

A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Per…

Fix: 1.49.16+
Fix from $2,300 2025-06-19
Unclassified HIGH 7.2
CVE-2025-23171

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit fil…

Mitigation only
Fix from $1,950 2025-06-19
Timetrax CRITICAL 9.9
CVE-2025-46157

An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form

Mitigation only
Fix from $2,300 2025-06-18
Ultimate Addons For Contact Form 7 HIGH 7.2
CVE-2025-6220

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_opt…

Fix: 3.5.13+
Fix from $1,950 2025-06-18
Unclassified HIGH 7.2
CVE-2025-6086

The CSV Me plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'csv_me_options_page' functio…

Mitigation only
Fix from $1,950 2025-06-18
Unclassified HIGH 8.8
CVE-2025-4413

The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in…

Mitigation only
Fix from $1,950 2025-06-18
Experience Commerce HIGH 8.8
CVE-2025-34511EPSS 16%

Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u…

Fix: 10.4+
Fix from $1,950 2025-06-17
Apex Central HIGH 7.5
CVE-2025-47866

An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary fil…

Mitigation only
Fix from $1,950 2025-06-17
Unclassified CRITICAL 10.0
CVE-2025-49444

Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor allows Upload a Web Shell to a W…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified CRITICAL 10.0
CVE-2025-49447

Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Food Menu allows Using Malicious Files. This issue affects FW Food M…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified CRITICAL 10.0
CVE-2025-49071

Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell to a Web Server.This issue a…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified CRITICAL 9.9
CVE-2025-47452

Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR wpvr allows Upload a Web Shell to a Web Server.This issue affects WP …

Mitigation only
Fix from $2,300 2025-06-17
Unclassified CRITICAL 9.9
CVE-2025-47559

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg allows Upload a Web Shell to a Web Server.This issue affects…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified CRITICAL 10.0
CVE-2025-32510

Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager ova-events-manager allows Using Malicious Files.Thi…

Mitigation only
Fix from $2,300 2025-06-17
Drag And Drop Multiple File Upload Contact Form 7 CRITICAL 9.8
CVE-2025-3515EPSS 5%

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type …

Fix: 1.3.9.0+
Fix from $2,300 2025-06-17
Simple Food Ordering System CRITICAL 9.8
CVE-2025-6161

A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of th…

Mitigation only
Fix from $2,300 2025-06-17
Unclassified HIGH 7.2
CVE-2025-3234

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up t…

Mitigation only
Fix from $1,950 2025-06-14
Workreap HIGH 8.8
CVE-2025-5012

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missi…

Fix: 3.3.3+
Fix from $1,950 2025-06-12
Unclassified HIGH 7.2
CVE-2025-6002

An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files wit…

Mitigation only
Fix from $1,950 2025-06-11
Unclassified HIGH 8.8
CVE-2025-5395

The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php…

Mitigation only
Fix from $1,950 2025-06-11
Easy Firmware HIGH 7.2
CVE-2025-46612

The Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a wizard/workspace.js…

Fix: 6.36+
Fix from $1,950 2025-06-10
Axle Demo Importer HIGH 8.8
CVE-2025-4954

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above…

Fix: after 1.0.3
Fix from $1,950 2025-06-10
Unclassified HIGH 8.8
CVE-2025-4387

The Abandoned Cart Pro for WooCommerce plugin contains an authenticated arbitrary file upload vulnerability due to missing file type validation in th…

Mitigation only
Fix from $1,950 2025-06-10
Unclassified CRITICAL 10.0
CVE-2025-32291

Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Using Malicious Files.This issue af…

Mitigation only
Fix from $2,300 2025-06-09
Unclassified MEDIUM 6.3
CVE-2025-5873

A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmwa…

Mitigation only
Fix from $1,600 2025-06-09
Manageengine Exchange Reporter Plus CRITICAL 9.6
CVE-2025-3835

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

Fix: 5.7+
Fix from $2,300 2025-06-09
Client Database Management System HIGH 7.3
CVE-2025-5840

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of…

No fix yet
Fix from $1,950 2025-06-07
Unclassified MEDIUM 6.6
CVE-2025-49329

Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to…

Mitigation only
Fix from $1,600 2025-06-06
Hr Portal CRITICAL 9.8
CVE-2025-48782

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System throu…

Fix: after 7.3.2025.0408
Fix from $2,300 2025-06-06
Open Source Clinic Management System HIGH 8.8
CVE-2025-5728

A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code …

No fix yet
Fix from $1,950 2025-06-06