Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.8
CVE-2024-11617

The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'zetra_languageUpload' and…

Mitigation only
Fix from $2,300 2025-05-09
Unclassified CRITICAL 9.8
CVE-2023-31585

Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php.

Mitigation only
Fix from $2,300 2025-05-08
Ultimate Before After Image Slider \& Gallery HIGH 7.2
CVE-2025-47549

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Upload a Web Shell to a Web Serve…

Fix: after 4.6.10
Fix from $1,950 2025-05-07
Instantio HIGH 7.2
CVE-2025-47550

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue af…

Fix: after 3.3.16
Fix from $1,950 2025-05-07
Unclassified HIGH 8.2
CVE-2025-0984

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab…

Mitigation only
Fix from $1,950 2025-05-06
Gim CRITICAL 9.8
CVE-2025-40625

Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…

Mitigation only
Fix from $2,300 2025-05-06
Unclassified MEDIUM 6.3
CVE-2025-4333

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function…

Mitigation only
Fix from $1,600 2025-05-06
Content Management System MEDIUM 6.3
CVE-2025-4310

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/…

No fix yet
Fix from $1,600 2025-05-06
Unclassified MEDIUM 6.3
CVE-2025-4305

A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file ap…

Mitigation only
Fix from $1,600 2025-05-06
Ideacms CRITICAL 9.8
CVE-2025-4291

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unr…

Fix: after 1.6
Fix from $2,300 2025-05-05
Unclassified HIGH 8.8
CVE-2025-4279

The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_re…

Mitigation only
Fix from $1,950 2025-05-05
Multiple File Upload CRITICAL 9.8
CVE-2025-28168

The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size…

Mitigation only
Fix from $2,300 2025-05-05
Newbee Mall CRITICAL 9.8
CVE-2025-4259

A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/n…

No fix yet
Fix from $2,300 2025-05-05
Youkefu HIGH 8.8
CVE-2025-4258

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youk…

Fix: after 4.2.0
Fix from $1,950 2025-05-05
April HIGH 8.8
CVE-2024-13418

Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() func…

Fix: after 7.1
Fix from $1,950 2025-05-02
Kibana MEDIUM 5.4
CVE-2024-11390

Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML a…

Fix: 7.17.24 / 8.12.0+
Fix from $1,600 2025-05-01
Domino Leap MEDIUM 5.4
CVE-2022-42449

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

Fix: 1.1.1+
Fix from $1,600 2025-04-30
Domino Leap MEDIUM 5.4
CVE-2022-27562

Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

Fix: 1.1.1+
Fix from $1,600 2025-04-30
Unclassified CRITICAL 9.4
CVE-2025-0520

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to re…

Patch available
Fix from $2,300 2025-04-29
News Publishing Site Dashboard CRITICAL 9.8
CVE-2025-3969

A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processi…

No fix yet
Fix from $2,300 2025-04-27
Aeropage Sync For Airtable HIGH 8.8
CVE-2025-3914EPSS 15%

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_medi…

Fix: 3.3.0+
Fix from $1,950 2025-04-26
Unclassified CRITICAL 9.9
CVE-2025-46616

Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO befo…

Mitigation only
Fix from $2,300 2025-04-25
Netweaver CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…

Mitigation only
Fix from $2,300 2025-04-24
Unclassified CRITICAL 9.9
CVE-2025-46264

Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload a Web Shell to a Web Server.T…

Mitigation only
Fix from $2,300 2025-04-24
Ddi CRITICAL 9.8
CVE-2025-43946

TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

Fix: after 11.34p1c2
Fix from $2,300 2025-04-22
Greenshift Animation And Page Builder Blocks HIGH 8.8
CVE-2025-3616

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i…

Fix: 11.4.6+
Fix from $1,950 2025-04-22
Mcms CRITICAL 9.8
CVE-2025-29287

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted fil…

No fix yet
Fix from $2,300 2025-04-21
Kuangsimplebbs CRITICAL 9.8
CVE-2025-3830

A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUplo…

No fix yet
Fix from $2,300 2025-04-20
My Bbs CRITICAL 9.8
CVE-2025-3807

A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com…

No fix yet
Fix from $2,300 2025-04-19
Wcms HIGH 7.2
CVE-2025-3798

A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminContr…

No fix yet
Fix from $1,950 2025-04-19