Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified HIGH 8.1
CVE-2025-1070

CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downlo…

Mitigation only
Fix from $1,950 2025-02-13
Maxtime HIGH 8.8
CVE-2025-26350

A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allow…

Fix: after 2.11.0
Fix from $1,950 2025-02-12
Brizy HIGH 8.8
CVE-2024-10960

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' funct…

Fix: 2.6.5+
Fix from $1,950 2025-02-12
Security \& Malware Scan CRITICAL 9.8
CVE-2024-13365

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip…

Fix: 2.150+
Fix from $2,300 2025-02-12
Unclassified HIGH 8.8
CVE-2024-13714

The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val…

Mitigation only
Fix from $1,950 2025-02-12
Unclassified HIGH 8.8
CVE-2025-26411

An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to …

Mitigation only
Fix from $1,950 2025-02-11
Food Menu Manager HIGH 8.8
CVE-2025-1166

A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $1,950 2025-02-11
Unclassified HIGH 7.3
CVE-2025-1165

A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUpl…

Mitigation only
Fix from $1,950 2025-02-11
Unclassified CRITICAL 9.8
CVE-2024-13011

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_prof…

Mitigation only
Fix from $2,300 2025-02-10
Unclassified HIGH 7.3
CVE-2024-57407

An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafte…

Mitigation only
Fix from $1,950 2025-02-10
Cool Admin Java HIGH 7.2
CVE-2024-57408

An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading…

No fix yet
Fix from $1,950 2025-02-10
Shopping Portal HIGH 8.8
CVE-2024-57668

In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.

No fix yet
Fix from $1,950 2025-02-06
Unclassified HIGH 7.5
CVE-2025-1025EPSS 19%

Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypa…

Patch available
Fix from $1,950 2025-02-05
Unclassified HIGH 8.1
CVE-2025-1028

The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the contact form upload featu…

Mitigation only
Fix from $1,950 2025-02-05
Unclassified HIGH 7.2
CVE-2024-13723

The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able …

Mitigation only
Fix from $1,950 2025-02-04
Veracore HIGH 8.8
CVE-2024-57968 KEVEPSS 32%

Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during w…

Fix: 2024.4.2.1+
Fix from $1,950 2025-02-03
Chestnutcms CRITICAL 9.8
CVE-2024-57450

ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.

Fix: after 1.5.0
Fix from $2,300 2025-02-03
Unclassified HIGH 8.8
CVE-2025-24505

This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a spec…

Mitigation only
Fix from $1,950 2025-01-30
Recipes MEDIUM 5.4
CVE-2025-23213

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitra…

Fix: 1.5.28+
Fix from $1,600 2025-01-28
Addons CRITICAL 9.8
CVE-2024-13448

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_…

Fix: 2.34.0+
Fix from $2,300 2025-01-28
Image Gallery Management System HIGH 7.2
CVE-2025-0722

A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.p…

No fix yet
Fix from $1,950 2025-01-27
Wpbookit CRITICAL 9.8
CVE-2025-0357

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::ha…

Fix: 1.6.10+
Fix from $2,300 2025-01-25
Tourfic CRITICAL 9.1
CVE-2025-24650

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a Web Server.This issue affect…

Fix: 2.15.4+
Fix from $2,300 2025-01-24
Bootplus HIGH 8.8
CVE-2025-0702

A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unk…

Fix: after 2020-08-24
Fix from $1,950 2025-01-24
Planning Analytics HIGH 8.0
CVE-2024-40693

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interfa…

Mitigation only
Fix from $1,950 2025-01-24
Planning Analytics HIGH 8.8
CVE-2024-25034

IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. At…

Mitigation only
Fix from $1,950 2025-01-24
Workplace Suite CRITICAL 9.8
CVE-2024-55926

A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By…

Fix: 5.6.701.9+
Fix from $2,300 2025-01-23
Unclassified CRITICAL 9.1
CVE-2025-23942

Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Upload a Web Shell to a Web Serve…

Mitigation only
Fix from $2,300 2025-01-22
Unclassified CRITICAL 10.0
CVE-2025-23953

Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web Shell to a Web Server.This iss…

Mitigation only
Fix from $2,300 2025-01-22
Unclassified CRITICAL 9.9
CVE-2025-23918

Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web She…

Mitigation only
Fix from $2,300 2025-01-22