Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.0
CVE-2025-23921

Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell …

Mitigation only
Fix from $2,300 2025-01-22
Wpot CRITICAL 9.8
CVE-2024-13091

The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_f…

Fix: 13.5.6+
Fix from $2,300 2025-01-22
Unclassified CRITICAL 9.1
CVE-2025-22723

Unrestricted Upload of File with Dangerous Type vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager bar…

Mitigation only
Fix from $2,300 2025-01-21
Unclassified CRITICAL 9.0
CVE-2024-51919

Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Produ…

Mitigation only
Fix from $2,300 2025-01-21
Tailoring Management System HIGH 7.2
CVE-2025-0582

A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the fil…

No fix yet
Fix from $1,950 2025-01-20
Advanced File Manager HIGH 7.5
CVE-2024-13333

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_sys…

Fix: 5.2.14+
Fix from $1,950 2025-01-17
Pmb HIGH 7.5
CVE-2025-0472

Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environ…

Fix: after 4.2.13
Fix from $1,950 2025-01-16
Pmb CRITICAL 9.8
CVE-2025-0471

Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload…

Mitigation only
Fix from $2,300 2025-01-16
Unclassified MEDIUM 5.4
CVE-2024-13355

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficien…

Mitigation only
Fix from $1,600 2025-01-16
Unclassified MEDIUM 6.5
CVE-2024-41454

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execu…

Mitigation only
Fix from $1,600 2025-01-15
Unclassified CRITICAL 9.9
CVE-2025-22782

Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce al…

Mitigation only
Fix from $2,300 2025-01-15
Jeewms HIGH 8.1
CVE-2024-57761

An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploadin…

Fix: 2025-01-01+
Fix from $1,950 2025-01-15
Gestioip CRITICAL 9.8
CVE-2024-48760EPSS 45%

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perl…

No fix yet
Fix from $2,300 2025-01-14
Endpoint Manager HIGH 7.8
CVE-2024-13171EPSS 18%

Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote…

Fix: 2022+
Fix from $1,950 2025-01-14
Lingdang Crm CRITICAL 9.8
CVE-2025-0463

A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an …

Mitigation only
Fix from $2,300 2025-01-14
Unclassified HIGH 7.3
CVE-2025-0460

A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file…

Mitigation only
Fix from $1,950 2025-01-14
Unclassified HIGH 8.8
CVE-2025-0394

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file upload…

Mitigation only
Fix from $1,950 2025-01-14
Visual Access Manager MEDIUM 6.5
CVE-2023-42248

An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating P…

Fix: 4.42.2+
Fix from $1,600 2025-01-13
Supravizio Bpm HIGH 8.8
CVE-2024-46479

Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a maliciou…

Fix: after 18.0.1
Fix from $1,950 2025-01-13
Reggie HIGH 8.8
CVE-2025-0402

A vulnerability classified as critical was found in 1902756969 reggie 1.0. Affected by this vulnerability is the function upload of the file src/main…

Mitigation only
Fix from $1,950 2025-01-13
Starsea Mall HIGH 7.2
CVE-2025-0399

A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController o…

Mitigation only
Fix from $1,950 2025-01-12
Dryice Myxalytics CRITICAL 9.8
CVE-2024-42180

HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types…

Mitigation only
Fix from $2,300 2025-01-12
Unclassified CRITICAL 9.1
CVE-2025-22152

Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple component…

Mitigation only
Fix from $2,300 2025-01-10
Redaxo HIGH 7.2
CVE-2024-46210

An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a craft…

Mitigation only
Fix from $1,950 2025-01-10
Unclassified CRITICAL 10.0
CVE-2025-22504

Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-webforms allows Upload a Web Shell to a Web Server.…

Mitigation only
Fix from $2,300 2025-01-09
Content Management System HIGH 7.2
CVE-2025-0346

A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the fil…

No fix yet
Fix from $1,950 2025-01-09
Computer Laboratory Management System CRITICAL 9.8
CVE-2025-0341

A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0. Affected by this issue is s…

No fix yet
Fix from $2,300 2025-01-09
Unclassified MEDIUM 5.3
CVE-2024-43662

The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any user, although the…

Mitigation only
Fix from $1,600 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43656

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified HIGH 8.8
CVE-2024-43657

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff…

Mitigation only
Fix from $1,950 2025-01-09