Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.0
CVE-2025-31916

Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium allows Upload a Web Shell to …

Mitigation only
Fix from $2,300 2025-05-23
Unclassified MEDIUM 6.7
CVE-2025-30173

File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: throu…

Mitigation only
Fix from $1,600 2025-05-22
Unclassified MEDIUM 6.7
CVE-2025-30169

File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affe…

Mitigation only
Fix from $1,600 2025-05-22
Manageengine Servicedesk Plus Msp MEDIUM 6.5
CVE-2025-3444

Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in …

Fix: after 14.8
Fix from $1,600 2025-05-22
Unclassified MEDIUM 6.4
CVE-2024-9544

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 8.6.4 due to …

Mitigation only
Fix from $1,600 2025-05-22
Online Shopping Portal HIGH 7.2
CVE-2025-5059

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown part of the file /admin/edit-s…

No fix yet
Fix from $1,950 2025-05-21
TYPO3 MEDIUM 5.4
CVE-2025-47939

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has histori…

Fix: 9.5.51 / 10.4.50+
Fix from $1,600 2025-05-20
Unclassified CRITICAL 10.0
CVE-2025-39401

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web Server.This i…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.9
CVE-2025-39402

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web Server.This i…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified CRITICAL 10.0
CVE-2025-39380

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management allows Upload a Web Shell to…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified CRITICAL 10.0
CVE-2025-47577

Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.9
CVE-2025-26872

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Eximius allows Using Malicious Files.This issue affects Eximius: from n/a th…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified CRITICAL 9.9
CVE-2025-26892

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aur…

Mitigation only
Fix from $2,300 2025-05-19
Car Rental Portal HIGH 7.2
CVE-2025-4926

A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is some unknown functionality of th…

No fix yet
Fix from $1,950 2025-05-19
Client Database Management System HIGH 7.3
CVE-2025-4923

A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some un…

No fix yet
Fix from $1,950 2025-05-19
Unclassified CRITICAL 9.8
CVE-2025-4391

The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generat…

Mitigation only
Fix from $2,300 2025-05-17
Unclassified CRITICAL 9.8
CVE-2025-4389

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Mitigation only
Fix from $2,300 2025-05-17
Unclassified MEDIUM 6.3
CVE-2025-4768

A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects the function uploadPicture o…

Mitigation only
Fix from $1,600 2025-05-16
Sales And Inventory System HIGH 8.8
CVE-2025-4735

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown f…

No fix yet
Fix from $1,950 2025-05-16
Emlog CRITICAL 9.8
CVE-2025-47787

Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component cont…

Fix: 2.5.10+
Fix from $2,300 2025-05-15
Unclassified CRITICAL 9.8
CVE-2025-3917

The 百度站长SEO合集(支持百度/神马/Bing/头条推送) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Mitigation only
Fix from $2,300 2025-05-15
Centreon Web MEDIUM 5.9
CVE-2025-4648

The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can i…

Fix: 22.10.29 / 23.04.27+
Fix from $1,600 2025-05-13
Unclassified HIGH 8.8
CVE-2025-4317

The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in a…

Mitigation only
Fix from $1,950 2025-05-13
Unclassified HIGH 8.8
CVE-2025-4561

The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell ba…

Mitigation only
Fix from $1,950 2025-05-12
Unclassified CRITICAL 9.8
CVE-2025-4556

The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated r…

Mitigation only
Fix from $2,300 2025-05-12
Kkfileview CRITICAL 9.8
CVE-2025-4538

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipula…

Mitigation only
Fix from $2,300 2025-05-11
Client Database Management System CRITICAL 9.8
CVE-2025-46193

SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.p…

Mitigation only
Fix from $2,300 2025-05-09
Unclassified CRITICAL 9.8
CVE-2025-4403

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and includ…

Mitigation only
Fix from $2,300 2025-05-09
Online Student Clearance System CRITICAL 9.8
CVE-2025-4468

A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This issue affects some unknown proce…

No fix yet
Fix from $2,300 2025-05-09
Unclassified HIGH 8.8
CVE-2025-3455

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized modification of data due to …

Mitigation only
Fix from $1,950 2025-05-09