Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified MEDIUM 6.3
CVE-2025-2706

A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/Ti…

Mitigation only
Fix from $1,600 2025-03-24
Unclassified HIGH 7.3
CVE-2025-2705

A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadAp…

Mitigation only
Fix from $1,950 2025-03-24
Unclassified MEDIUM 6.3
CVE-2025-2702

A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd…

Mitigation only
Fix from $1,600 2025-03-24
Elearning System CRITICAL 9.8
CVE-2025-2687

A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php…

No fix yet
Fix from $2,300 2025-03-24
Unclassified MEDIUM 6.3
CVE-2025-2671

A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64im…

Mitigation only
Fix from $1,600 2025-03-23
Best Church Management Software MEDIUM 6.3
CVE-2025-2606

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is …

No fix yet
Fix from $1,600 2025-03-21
Lzcms Laozhangbokexitong MEDIUM 6.3
CVE-2025-2607

A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected by this issue is some unknown …

Fix: after 1.1.4
Fix from $1,600 2025-03-21
Ibanking CRITICAL 9.8
CVE-2025-29411

An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary …

No fix yet
Fix from $2,300 2025-03-20
Lollms Web Ui HIGH 8.8
CVE-2024-9920

In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangero…

No fix yet
Fix from $1,950 2025-03-20
Composio CRITICAL 9.8
CVE-2024-8958

In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation…

No fix yet
Fix from $2,300 2025-03-20
Pytorch Lightning CRITICAL 9.1
CVE-2024-8019

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occur…

Patch available
Fix from $2,300 2025-03-20
Db Gpt CRITICAL 9.8
CVE-2024-10901

In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access contr…

No fix yet
Fix from $2,300 2025-03-20
Emlog MEDIUM 6.3
CVE-2025-29405

An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary co…

Fix: after 2.5.7
Fix from $1,600 2025-03-19
File Away CRITICAL 9.8
CVE-2025-2512

The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the …

Fix: after 3.9.9.0.1
Fix from $2,300 2025-03-19
Glpi HIGH 8.8
CVE-2025-24801EPSS 20%

GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI …

Fix: 10.0.18+
Fix from $1,950 2025-03-18
Soplanning CRITICAL 9.8
CVE-2024-57169

A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to b…

No fix yet
Fix from $2,300 2025-03-18
Softdial Contact Center CRITICAL 9.8
CVE-2025-2494

Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/…

Mitigation only
Fix from $2,300 2025-03-18
Ipados HIGH 8.8
CVE-2024-54525

A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2…

Fix: 2.2 / 11.2+
Fix from $1,950 2025-03-17
U Office Force HIGH 8.8
CVE-2025-2396

The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and exec…

Fix: 28.0+
Fix from $1,950 2025-03-17
Fx2 Firmware HIGH 7.8
CVE-2025-2350

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown functionality o…

Fix: after 2025-03-08
Fix from $1,950 2025-03-16
Lovecards CRITICAL 9.8
CVE-2025-2219

A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /ap…

Fix: after 2.3.2
Fix from $2,300 2025-03-12
Warehouse Refinement Management System CRITICAL 9.8
CVE-2025-2216

A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the…

No fix yet
Fix from $2,300 2025-03-12
Unclassified CRITICAL 9.1
CVE-2025-28915

Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Serve…

Mitigation only
Fix from $2,300 2025-03-11
Unclassified HIGH 7.1
CVE-2025-22213

Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other…

Mitigation only
Fix from $1,950 2025-03-11
Warehouse Refinement Management System CRITICAL 9.8
CVE-2025-2115

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRe…

No fix yet
Fix from $2,300 2025-03-09
Product Input Fields For Woocommerce CRITICAL 9.8
CVE-2024-13359

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the…

Fix: 1.12.2+
Fix from $2,300 2025-03-08
Aiomatic HIGH 8.8
CVE-2024-13882

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file…

Fix: 2.3.9+
Fix from $1,950 2025-03-08
Smtp HIGH 7.2
CVE-2024-13908

The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' functi…

Fix: 1.2.0+
Fix from $1,950 2025-03-08
Publiccms CRITICAL 9.8
CVE-2025-25361

An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi…

No fix yet
Fix from $2,300 2025-03-06
Ecommerce Website Using Php CRITICAL 9.8
CVE-2025-2035

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality…

No fix yet
Fix from $2,300 2025-03-06