Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified HIGH 8.8
CVE-2025-3054

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() funct…

Mitigation only
Fix from $1,950 2025-06-05
Identity Services Engine HIGH 7.2
CVE-2025-20130

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, r…

Fix: 3.1.0+
Fix from $1,950 2025-06-04
Content Management System HIGH 8.2
CVE-2025-29093

File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Ima…

No fix yet
Fix from $1,950 2025-06-04
Umbraco Cms MEDIUM 6.5
CVE-2025-48953

Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a …

Fix: 15.4.2+
Fix from $1,600 2025-06-03
Erupt MEDIUM 5.4
CVE-2025-45855

An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via …

Fix: after 1.12.19
Fix from $1,600 2025-06-03
Unclassified MEDIUM 6.4
CVE-2025-1725

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Mitigation only
Fix from $1,600 2025-06-03
Unclassified MEDIUM 6.8
CVE-2024-7074EPSS 12%

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious …

Mitigation only
Fix from $1,600 2025-06-02
Blogbook HIGH 8.8
CVE-2025-5406

A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an…

Fix: after 2021-11-22
Fix from $1,950 2025-06-01
Gradio HIGH 7.5
CVE-2025-48889

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py…

Fix: 5.31.0+
Fix from $1,950 2025-05-30
Freescout CRITICAL 9.8
CVE-2025-48471

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs insufficient check…

Fix: 1.8.179+
Fix from $2,300 2025-05-29
Huocms MEDIUM 5.3
CVE-2025-46078

HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server

No fix yet
Fix from $1,600 2025-05-29
Huocms MEDIUM 5.3
CVE-2025-46080

HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with spec…

No fix yet
Fix from $1,600 2025-05-29
Web Based Pharmacy Product Management System HIGH 8.6
CVE-2025-45997

Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an …

No fix yet
Fix from $1,950 2025-05-28
Client Database Management System HIGH 7.3
CVE-2025-5299

A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unkno…

No fix yet
Fix from $1,950 2025-05-28
Unclassified HIGH 8.8
CVE-2025-4800

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignm…

Mitigation only
Fix from $1,950 2025-05-28
Queue Ticket Kiosk CRITICAL 9.8
CVE-2025-5178

A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the …

Fix: after 2025-05-17
Fix from $2,300 2025-05-26
Mta Maita Training System CRITICAL 9.8
CVE-2025-5171

A vulnerability, which was classified as critical, has been found in llisoft MTA Maita Training System 4.5. This issue affects the function this.file…

Mitigation only
Fix from $2,300 2025-05-26
Seccenter Smp 1114p02 CRITICAL 9.8
CVE-2025-5162

A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknow…

Fix: after 20250513
Fix from $2,300 2025-05-26
Tmall Demo HIGH 7.2
CVE-2025-5131

A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the function uploadCategoryImage…

Fix: after 2025-05-05
Fix from $1,950 2025-05-24
Tmall Demo HIGH 7.2
CVE-2025-5130

A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function uploadProductImage of the file …

Fix: after 2025-05-05
Fix from $1,950 2025-05-24
Emagicone Store Manager For Woocommerce CRITICAL 9.8
CVE-2025-5058

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s…

Fix: after 1.2.5
Fix from $2,300 2025-05-24
Emagicone Store Manager For Woocommerce CRITICAL 9.8
CVE-2025-4336

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s…

Fix: after 1.2.5
Fix from $2,300 2025-05-24
Shopxo CRITICAL 9.8
CVE-2025-5108

A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/cont…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 10.0
CVE-2025-47687

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Uplo…

Mitigation only
Fix from $2,300 2025-05-23
Wsdesk HIGH 8.8
CVE-2025-47658

Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-custo…

Fix: 3.3.0+
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.9
CVE-2025-47663

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This …

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 10.0
CVE-2025-47637

Unrestricted Upload of File with Dangerous Type vulnerability in STAGGS STAGGS staggs allows Upload a Web Shell to a Web Server.This issue affects ST…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 10.0
CVE-2025-47641

Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integrat…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 10.0
CVE-2025-47642

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.9
CVE-2025-46490

Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Upload …

Mitigation only
Fix from $2,300 2025-05-23