Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified MEDIUM 5.4
CVE-2026-39527

Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.

Mitigation only
Fix from $1,600 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50873

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via upload…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2018-25436

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified MEDIUM 5.3
CVE-2026-34027

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/u…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified CRITICAL 9.3
CVE-2026-5482

Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified HIGH 8.7
CVE-2026-6211

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properl…

Mitigation only
Fix from $1,950 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-53787EPSS 5%

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticate…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified HIGH 8.1
CVE-2026-46489

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation.…

Patch available
Fix from $1,950 2026-06-11
Unclassified CRITICAL 9.9
CVE-2026-11839

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web S…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.8
CVE-2026-7852

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects Lim…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.1
CVE-2026-9067

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and…

Mitigation only
Fix from $2,300 2026-06-10
Unclassified MEDIUM 5.4
CVE-2026-36722

An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary co…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.1
CVE-2025-40808

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (Al…

Mitigation only
Fix from $1,600 2026-06-09
Answer MEDIUM 6.5
CVE-2026-33582

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF ima…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Answer MEDIUM 6.5
CVE-2026-34031

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not…

Fix: 2.0.1+
Fix from $1,600 2026-06-09
Unclassified CRITICAL 9.8
CVE-2024-58348

WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitra…

Mitigation only
Fix from $2,300 2026-06-08
Unclassified CRITICAL 9.8
CVE-2024-58349

WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by …

Mitigation only
Fix from $2,300 2026-06-08
Unclassified HIGH 7.3
CVE-2026-11474

A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown func…

Mitigation only
Fix from $1,950 2026-06-08
Unclassified HIGH 7.2
CVE-2026-7537

The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send…

Mitigation only
Fix from $1,950 2026-06-06
Unclassified HIGH 8.7
CVE-2026-46400

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload function…

Mitigation only
Fix from $1,950 2026-06-05
On Prem Enterprise Server HIGH 8.8
CVE-2026-11419

A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled …

Fix: 8.1.1+
Fix from $1,950 2026-06-05
Unclassified HIGH 8.8
CVE-2026-5411

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbit…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 8.7
CVE-2026-46392

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified HIGH 7.3
CVE-2026-11344

A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component…

Mitigation only
Fix from $1,950 2026-06-05
Unclassified MEDIUM 6.3
CVE-2026-11333

A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dc…

Mitigation only
Fix from $1,600 2026-06-05
Unclassified MEDIUM 6.3
CVE-2026-42538

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not pr…

Mitigation only
Fix from $1,600 2026-06-04
Unclassified MEDIUM 6.3
CVE-2026-10806

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.ph…

Mitigation only
Fix from $1,600 2026-06-04
Unclassified MEDIUM 6.3
CVE-2026-10807

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/chang…

Mitigation only
Fix from $1,600 2026-06-04
Unclassified MEDIUM 6.4
CVE-2026-40548

SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archiv…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10205

A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systpa…

Mitigation only
Fix from $1,600 2026-06-01