Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Haxcms Php CRITICAL 9.9
CVE-2025-32028

HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’…

Fix: 10.0.3+
Fix from $2,300 2025-04-08
Aias HIGH 8.8
CVE-2025-3410

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform…

No fix yet
Fix from $1,950 2025-04-08
Unclassified HIGH 8.8
CVE-2025-2525

The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_Authentication_Controller::ed…

Mitigation only
Fix from $1,950 2025-04-08
Nimrod HIGH 8.8
CVE-2025-3324

A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown funct…

No fix yet
Fix from $1,950 2025-04-06
Xperience CRITICAL 9.8
CVE-2025-32370

Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is…

Fix: 13.0.178+
Fix from $2,300 2025-04-06
Maximo Application Suite HIGH 8.0
CVE-2025-1500

IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if op…

Fix: 9.0.7+
Fix from $1,950 2025-04-05
Unclassified CRITICAL 9.1
CVE-2025-32118

Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using…

Mitigation only
Fix from $2,300 2025-04-04
Web Based Pharmacy Product Management System HIGH 8.8
CVE-2025-3244

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vuln…

No fix yet
Fix from $1,950 2025-04-04
Woffice HIGH 8.8
CVE-2025-2780

The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the …

Fix: 5.4.22+
Fix from $1,950 2025-04-04
Booster For Woocommerce HIGH 7.2
CVE-2024-13708

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to …

Fix: 7.2.5+
Fix from $1,950 2025-04-04
Booster For Woocommerce CRITICAL 9.8
CVE-2024-13744

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_…

Fix: 7.2.5+
Fix from $2,300 2025-04-04
Unclassified MEDIUM 5.0
CVE-2025-3169

A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

No fix yet
Fix from $1,600 2025-04-03
Wondercms HIGH 7.2
CVE-2025-3123

A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleActio…

No fix yet
Fix from $1,950 2025-04-02
Front End Users CRITICAL 9.8
CVE-2025-2005EPSS 20%

The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the…

Fix: after 3.2.32
Fix from $2,300 2025-04-02
Wyse Management Suite HIGH 7.2
CVE-2025-27692

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged a…

Fix: 5.1+
Fix from $1,950 2025-04-02
Unclassified HIGH 8.8
CVE-2025-2891

The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-…

Mitigation only
Fix from $1,950 2025-04-01
Unclassified HIGH 8.8
CVE-2025-2008

The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Mitigation only
Fix from $1,950 2025-04-01
Online Time Table Generator CRITICAL 9.8
CVE-2025-3042

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the fi…

No fix yet
Fix from $2,300 2025-04-01
Online Time Table Generator CRITICAL 9.8
CVE-2025-3041

A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /ad…

No fix yet
Fix from $2,300 2025-04-01
Online Time Table Generator CRITICAL 9.8
CVE-2025-3040

A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown fu…

No fix yet
Fix from $2,300 2025-03-31
Unclassified MEDIUM 6.6
CVE-2025-31577

Unrestricted Upload of File with Dangerous Type vulnerability in appointify Appointify appointify allows Upload a Web Shell to a Web Server.This issu…

Mitigation only
Fix from $1,600 2025-03-31
Wcms CRITICAL 9.8
CVE-2025-2978

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?arti…

No fix yet
Fix from $2,300 2025-03-31
College Management System CRITICAL 9.8
CVE-2025-2973

A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file…

No fix yet
Fix from $2,300 2025-03-31
Micro Mall CRITICAL 9.8
CVE-2025-2952

A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /…

No fix yet
Fix from $2,300 2025-03-30
Unclassified HIGH 8.8
CVE-2025-2006

The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file…

Mitigation only
Fix from $1,950 2025-03-29
Unclassified HIGH 8.8
CVE-2025-2249

The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_s…

Mitigation only
Fix from $1,950 2025-03-29
Invoiceplane CRITICAL 9.8
CVE-2024-56975

InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method o…

Fix: 1.6.2+
Fix from $2,300 2025-03-28
Unclassified MEDIUM 6.6
CVE-2025-2819

There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection pro…

Mitigation only
Fix from $1,600 2025-03-26
Xperience MEDIUM 6.1
CVE-2025-2748EPSS 59%

The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for store…

Fix: after 13.0.178
Fix from $1,600 2025-03-24
Xperience HIGH 7.2
CVE-2025-2749 KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative …

Fix: after 13.0.178
Fix from $1,950 2025-03-24