Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Online Bike Rental System CRITICAL 9.8
CVE-2025-0335

A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this issue is some unknown functiona…

No fix yet
Fix from $2,300 2025-01-09
Houserent HIGH 8.8
CVE-2024-13212

A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/jav…

Mitigation only
Fix from $1,950 2025-01-09
Bookstore HIGH 7.2
CVE-2024-13210

A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the functio…

No fix yet
Fix from $1,950 2025-01-09
Springboot Blog HIGH 7.2
CVE-2024-13201

A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the fi…

No fix yet
Fix from $1,950 2025-01-09
Myblog CRITICAL 9.8
CVE-2024-13191

A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/…

No fix yet
Fix from $2,300 2025-01-08
Unclassified CRITICAL 9.8
CVE-2025-22137

Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated…

Patch available
Fix from $2,300 2025-01-08
Unclassified HIGH 8.8
CVE-2024-12854

The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that a…

Mitigation only
Fix from $1,950 2025-01-08
Modula Image Gallery HIGH 8.8
CVE-2024-12853

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functiona…

Fix: 2.11.11+
Fix from $1,950 2025-01-08
Wegia CRITICAL 9.9
CVE-2025-22133

WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controll…

Fix: 3.2.8+
Fix from $2,300 2025-01-07
Unclassified CRITICAL 9.8
CVE-2022-41573

An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file c…

No fix yet
Fix from $2,300 2025-01-07
Clipbucket CRITICAL 9.8
CVE-2025-21624

ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functional…

Fix: 5.5.1-239+
Fix from $2,300 2025-01-07
Unclassified HIGH 8.8
CVE-2024-53345

An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uplo…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified CRITICAL 10.0
CVE-2024-43243

Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows Upload a Web Shell to a Web Se…

Mitigation only
Fix from $2,300 2025-01-07
Chestnutcms CRITICAL 9.8
CVE-2024-56828

File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receiv…

Fix: after 1.5.0
Fix from $2,300 2025-01-06
My Blog CRITICAL 9.8
CVE-2024-13145

A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/mai…

No fix yet
Fix from $2,300 2025-01-06
My Blog CRITICAL 9.8
CVE-2024-13144

A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/ja…

No fix yet
Fix from $2,300 2025-01-06
Mysiteforme HIGH 8.8
CVE-2024-13138

A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file …

No fix yet
Fix from $1,950 2025-01-05
Studentmanager HIGH 8.8
CVE-2024-13134

A vulnerability, which was classified as critical, was found in ZeroWdd studentmanager 1.0. Affected is the function addTeacher/editTeacher of the fi…

Mitigation only
Fix from $1,950 2025-01-05
Studentmanager HIGH 8.8
CVE-2024-13133

A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStude…

Mitigation only
Fix from $1,950 2025-01-05
Project Management System CRITICAL 9.8
CVE-2025-0213

A vulnerability was found in Campcodes Project Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of th…

No fix yet
Fix from $2,300 2025-01-04
Optimizely Cms HIGH 8.0
CVE-2025-22389

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application doe…

Fix: 12.32.0+
Fix from $1,950 2025-01-04
Unclassified CRITICAL 9.8
CVE-2024-55078

An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary cod…

Mitigation only
Fix from $2,300 2025-01-03
Unclassified MEDIUM 6.6
CVE-2024-56264

Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload a Web Shell to a Web Server.T…

Mitigation only
Fix from $1,600 2025-01-02
Unclassified CRITICAL 9.1
CVE-2024-56249

Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server…

Mitigation only
Fix from $2,300 2025-01-02
Unclassified CRITICAL 10.0
CVE-2024-56829

Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFi…

Mitigation only
Fix from $2,300 2025-01-02
Unclassified CRITICAL 10.0
CVE-2024-56064EPSS 30%

Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Ser…

Mitigation only
Fix from $2,300 2024-12-31
Wordpress Learning Management System CRITICAL 9.8
CVE-2024-56046

Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a…

Fix: 1.9.9.1+
Fix from $2,300 2024-12-31
Tarzan Cms CRITICAL 9.8
CVE-2024-13022

A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/mai…

No fix yet
Fix from $2,300 2024-12-29
Linkace HIGH 7.6
CVE-2024-56508

LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerability exists in the LinkAce. This…

Fix: 1.15.6+
Fix from $1,950 2024-12-27
Portfolio Management System Mca CRITICAL 9.8
CVE-2024-12956

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing…

No fix yet
Fix from $2,300 2024-12-26