Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.8
CVE-2021-4455

The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver…

No fix yet
Fix from $2,300 2025-04-19
Unclassified CRITICAL 9.8
CVE-2025-1093

The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versi…

Mitigation only
Fix from $2,300 2025-04-19
Web Based Pharmacy Product Management System CRITICAL 9.8
CVE-2025-3783

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability i…

No fix yet
Fix from $2,300 2025-04-18
Web Based Pharmacy Product Management System HIGH 8.8
CVE-2025-3764

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unkno…

No fix yet
Fix from $1,950 2025-04-17
Web Based Pharmacy Product Management System HIGH 8.8
CVE-2025-3765

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affe…

No fix yet
Fix from $1,950 2025-04-17
Unclassified CRITICAL 9.1
CVE-2025-39436

Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.9
CVE-2025-32682

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a …

Mitigation only
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.9
CVE-2025-32652

Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicious Files.This issue affects S…

Mitigation only
Fix from $2,300 2025-04-17
Js Job Manager CRITICAL 9.8
CVE-2025-32660

Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager js-jobs allows Upload a Web Shell to a Web Server.This issue …

Fix: after 2.0.2
Fix from $2,300 2025-04-17
Unclassified CRITICAL 9.9
CVE-2025-27282

Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator allows Using Malicious Files.…

Mitigation only
Fix from $2,300 2025-04-17
Unclassified MEDIUM 5.3
CVE-2025-31339

An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allo…

Mitigation only
Fix from $1,600 2025-04-17
Online Id Generator System CRITICAL 9.8
CVE-2024-40071

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSetting…

No fix yet
Fix from $2,300 2025-04-16
Unclassified CRITICAL 9.1
CVE-2025-39557

Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allo…

Mitigation only
Fix from $2,300 2025-04-16
Unclassified MEDIUM 6.6
CVE-2025-39538

Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search allows Upload a Web Shell to …

Mitigation only
Fix from $1,600 2025-04-16
Unclassified CRITICAL 9.4
CVE-2025-1980

The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If the server is misconfigured, …

Mitigation only
Fix from $2,300 2025-04-16
Unclassified CRITICAL 10.0
CVE-2025-26927

Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to a Web Server.This issue affec…

Mitigation only
Fix from $2,300 2025-04-15
My Blog Layui CRITICAL 9.8
CVE-2025-3593

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Up…

No fix yet
Fix from $2,300 2025-04-14
Cicadascms HIGH 8.8
CVE-2025-3585

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component J…

No fix yet
Fix from $1,950 2025-04-14
Unclassified HIGH 7.3
CVE-2025-3566

A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the function uploadMdPic…

Mitigation only
Fix from $1,950 2025-04-14
Studentmanager HIGH 7.2
CVE-2025-3565

A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /u…

No fix yet
Fix from $1,950 2025-04-14
Uzy Ssm Mall CRITICAL 9.8
CVE-2025-3558

A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uplo…

No fix yet
Fix from $2,300 2025-04-14
Unclassified CRITICAL 9.9
CVE-2025-32579

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.T…

Mitigation only
Fix from $2,300 2025-04-11
Internet Banking System HIGH 8.8
CVE-2025-29017

A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_…

No fix yet
Fix from $1,950 2025-04-10
Unclassified MEDIUM 6.5
CVE-2025-32215

Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Stored XSS.This issue a…

Mitigation only
Fix from $1,600 2025-04-10
Unclassified CRITICAL 9.1
CVE-2025-32202

Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress in…

Mitigation only
Fix from $2,300 2025-04-10
Unclassified CRITICAL 9.1
CVE-2025-32206

Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Se…

Mitigation only
Fix from $2,300 2025-04-10
Unclassified CRITICAL 9.9
CVE-2025-32140

Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell t…

Mitigation only
Fix from $2,300 2025-04-10
Unclassified CRITICAL 9.1
CVE-2025-31002

Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Malicious Files.This issue affects Sq…

Mitigation only
Fix from $2,300 2025-04-09
Unclassified HIGH 8.1
CVE-2025-29394

An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type.

Mitigation only
Fix from $1,950 2025-04-09
Arubaos HIGH 7.2
CVE-2025-27082

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operat…

Fix: 8.10.0.16 / 8.12.0.4+
Fix from $1,950 2025-04-08