Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Chestnutcms HIGH 7.6
CVE-2025-2031

A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/…

No fix yet
Fix from $1,950 2025-03-06
Redaxo MEDIUM 5.4
CVE-2025-27411

REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5…

Fix: 5.18.3+
Fix from $1,600 2025-03-05
Vasion Print HIGH 8.8
CVE-2025-27683

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dange…

Fix: 1.0.735 / 20.0.1330+
Fix from $1,950 2025-03-05
Flowise CRITICAL 9.8
CVE-2025-26319EPSS 56%

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

Patch available
Fix from $2,300 2025-03-04
Axis Os HIGH 7.1
CVE-2024-47259

Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation a…

Fix: 11.11.126 / 12.2.52+
Fix from $1,950 2025-03-04
Shishuocms CRITICAL 9.8
CVE-2025-1890

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/ma…

No fix yet
Fix from $2,300 2025-03-04
Unclassified MEDIUM 6.3
CVE-2025-1835

A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /ap…

Mitigation only
Fix from $1,600 2025-03-02
Zz CRITICAL 9.8
CVE-2025-1834

A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipu…

Fix: after 2024-8
Fix from $2,300 2025-03-02
Zz CRITICAL 9.8
CVE-2025-1818

A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file s…

Fix: after 2024-8
Fix from $2,300 2025-03-02
Skycaiji CRITICAL 9.8
CVE-2025-1791

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vend…

Mitigation only
Fix from $2,300 2025-03-01
Woocommerce Ultimate Gift Card CRITICAL 9.8
CVE-2024-8425

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_…

Fix: after 2.6.0
Fix from $2,300 2025-02-28
Shopxo CRITICAL 9.8
CVE-2025-26325

ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.

No fix yet
Fix from $2,300 2025-02-27
Vigor165 Firmware HIGH 8.8
CVE-2024-41339

An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vi…

Fix: 3.9.8 / 3.9.8.9+
Fix from $1,950 2025-02-27
Vigor165 Firmware HIGH 8.4
CVE-2024-41340

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 pri…

Fix: 3.9.8 / 3.9.8.9+
Fix from $1,950 2025-02-27
Emlog CRITICAL 9.8
CVE-2025-25783

An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading…

Mitigation only
Fix from $2,300 2025-02-26
Jizhicms CRITICAL 9.8
CVE-2025-25784

An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via u…

No fix yet
Fix from $2,300 2025-02-26
Foxcms CRITICAL 9.8
CVE-2025-25790

An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via…

No fix yet
Fix from $2,300 2025-02-26
Unclassified MEDIUM 6.5
CVE-2025-0731

An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in …

Mitigation only
Fix from $1,600 2025-02-26
Everest Forms CRITICAL 9.8
CVE-2025-1128EPSS 29%

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file…

Fix: 3.0.9.5+
Fix from $2,300 2025-02-25
Unclassified HIGH 7.3
CVE-2025-1646

A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file …

Mitigation only
Fix from $1,950 2025-02-25
Yi Car Dashcam Firmware CRITICAL 9.8
CVE-2024-56897

Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can al…

No fix yet
Fix from $2,300 2025-02-24
Best Church Management Software CRITICAL 9.8
CVE-2025-1598

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is …

No fix yet
Fix from $2,300 2025-02-24
Best Employee Management System CRITICAL 9.8
CVE-2025-1593

A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file…

Mitigation only
Fix from $2,300 2025-02-23
E Learning System HIGH 7.2
CVE-2025-1590

A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /a…

Mitigation only
Fix from $1,950 2025-02-23
Unclassified CRITICAL 10.0
CVE-2025-26776

Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Cha…

Mitigation only
Fix from $2,300 2025-02-22
Wpvivid Backup \& Migration HIGH 7.2
CVE-2024-13869

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val…

Fix: 0.9.113+
Fix from $1,950 2025-02-22
Education And Training System CRITICAL 9.8
CVE-2025-1555

A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. …

Mitigation only
Fix from $2,300 2025-02-21
Unclassified CRITICAL 10.0
CVE-2025-22654

Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious Files.This issue affects Simpl…

Mitigation only
Fix from $2,300 2025-02-18
Orca Hcm HIGH 8.8
CVE-2025-1388

Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web sh…

Fix: 11.0+
Fix from $1,950 2025-02-17
Library Card System CRITICAL 9.8
CVE-2025-1355

A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $2,300 2025-02-16