Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified MEDIUM 6.3
CVE-2026-10172

A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file ap…

Mitigation only
Fix from $1,600 2026-05-31
Unclassified HIGH 8.8
CVE-2018-25409

SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code th…

No fix yet
Fix from $1,950 2026-05-30
Unclassified HIGH 8.8
CVE-2018-25388

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type val…

No fix yet
Fix from $1,950 2026-05-29
Unclassified HIGH 7.3
CVE-2026-39292

Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote at…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified HIGH 7.2
CVE-2026-10072

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-10071

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web she…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 7.3
CVE-2026-30761

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute …

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.8
CVE-2026-9227

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gute…

Patch available
Fix from $1,950 2026-05-28
Unclassified HIGH 8.8
CVE-2026-9009

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.3
CVE-2026-42879

FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability e…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified HIGH 7.6
CVE-2026-46426

Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.2
CVE-2026-45089

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the outp…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-42748

Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified MEDIUM 6.3
CVE-2026-9445

A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified HIGH 7.3
CVE-2026-9421

A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the compo…

Mitigation only
Fix from $1,950 2026-05-25
Unclassified MEDIUM 6.3
CVE-2026-9374

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the c…

Mitigation only
Fix from $1,600 2026-05-24
Azure Orbital Spatio CRITICAL 9.8
CVE-2026-40412

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-22
Unclassified MEDIUM 6.9
CVE-2026-9053

Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file p…

Mitigation only
Fix from $1,600 2026-05-22
Unclassified CRITICAL 9.8
CVE-2026-6960

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_s…

Mitigation only
Fix from $2,300 2026-05-21
Concrete Cms HIGH 7.2
CVE-2026-8134

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page ty…

Fix: after 9.5.0
Fix from $1,950 2026-05-21
Unclassified HIGH 8.4
CVE-2026-9157

Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issu…

Mitigation only
Fix from $1,950 2026-05-21
Unclassified CRITICAL 9.4
CVE-2026-9102

A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file uploa…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 10.0
CVE-2026-45444

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue a…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-6555

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an arra…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-4883

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_buil…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified CRITICAL 9.8
CVE-2026-4885

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_aja…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified HIGH 7.2
CVE-2026-27891

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() fu…

Patch available
Fix from $1,950 2026-05-18
Unclassified HIGH 7.3
CVE-2026-8758

A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp.…

Mitigation only
Fix from $1,950 2026-05-17
Unclassified HIGH 8.8
CVE-2020-37227

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension vali…

No fix yet
Fix from $1,950 2026-05-16
Open Webui HIGH 8.7
CVE-2026-45315

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload end…

Fix: 0.9.3+
Fix from $1,950 2026-05-15