Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.8
CVE-2026-58480

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upl…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 8.8
CVE-2026-14489

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ve…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-14158

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_v…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.7
CVE-2026-55633

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an aut…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 7.2
CVE-2026-23698

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-l…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 8.8
CVE-2026-23697

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uplo…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-14345

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all ve…

Mitigation only
Fix from $2,300 2026-07-07
Arcgis Server CRITICAL 9.8
CVE-2026-9182

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi…

Fix: after 12.0
Fix from $2,300 2026-07-06
Iotdb CRITICAL 9.8
CVE-2026-24014

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14777

A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functiona…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.3
CVE-2026-14775

A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /pro…

Mitigation only
Fix from $1,600 2026-07-05
Unclassified MEDIUM 6.3
CVE-2026-14776

A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the funct…

Mitigation only
Fix from $1,600 2026-07-05
Unclassified HIGH 7.3
CVE-2026-14736

A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Perform…

Mitigation only
Fix from $1,950 2026-07-05
Unclassified MEDIUM 6.3
CVE-2026-14698

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown functio…

Mitigation only
Fix from $1,600 2026-07-05
Unclassified CRITICAL 9.8
CVE-2024-14037

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading …

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2022-50973

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-5524

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.9
CVE-2026-27419

Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.

No fix yet
Fix from $2,300 2026-07-02
Mycomplianceoffice MEDIUM 6.5
CVE-2026-53909

MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse…

Mitigation only
Fix from $1,600 2026-07-01
Coldfusion CRITICAL 10.0
CVE-2026-48276EPSS 5%

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48283

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified HIGH 8.6
CVE-2026-53691

An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/…

Mitigation only
Fix from $1,950 2026-06-30
Mantaray Nm HIGH 7.8
CVE-2025-24815

Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could all…

Fix: 25R2-NM+
Fix from $1,950 2026-06-30
Page Builder Ck CRITICAL 9.8
CVE-2026-56290 KEVEPSS 83%

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl…

Fix: 3.6.0+
Fix from $2,300 2026-06-29
Unclassified HIGH 8.6
CVE-2026-13165

SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with …

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13553

A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.3
CVE-2026-13547

A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.2
CVE-2026-56414

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed,…

Mitigation only
Fix from $1,950 2026-06-26
Dmp 5000 Firmware HIGH 8.8
CVE-2026-33560

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to …

Fix: 8.117.0.0 / 9.43.0.0+
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.1
CVE-2026-57658

Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.

Mitigation only
Fix from $2,300 2026-06-26