Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Open Webui CRITICAL 9.8
CVE-2026-44566

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp,…

Fix: 0.1.124+
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.8
CVE-2021-47965

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers …

Mitigation only
Fix from $2,300 2026-05-15
Unclassified HIGH 8.6
CVE-2026-44088

SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes u…

Mitigation only
Fix from $1,950 2026-05-15
Strapi MEDIUM 5.4
CVE-2026-22707

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not en…

Fix: 5.33.3+
Fix from $1,600 2026-05-14
Unclassified HIGH 7.2
CVE-2026-41937

Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitr…

Patch available
Fix from $1,950 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-6271

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. T…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.1
CVE-2026-45053

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager …

Mitigation only
Fix from $2,300 2026-05-13
Unclassified HIGH 7.3
CVE-2026-37430

An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitr…

Mitigation only
Fix from $1,950 2026-05-13
Grav HIGH 8.8
CVE-2026-42844

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upl…

No fix yet
Fix from $1,950 2026-05-12
Unclassified HIGH 8.0
CVE-2023-27753

An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Mitigation only
Fix from $1,950 2026-05-12
Unclassified MEDIUM 6.3
CVE-2025-65416

docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 8.8
CVE-2021-47943

TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading m…

No fix yet
Fix from $1,950 2026-05-10
Unclassified HIGH 8.8
CVE-2021-47937

e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrar…

No fix yet
Fix from $1,950 2026-05-10
Unclassified MEDIUM 6.3
CVE-2025-67886

Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execu…

Mitigation only
Fix from $1,600 2026-05-08
Unclassified MEDIUM 6.5
CVE-2026-36387

A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the fi…

Mitigation only
Fix from $1,600 2026-05-07
Unclassified HIGH 8.8
CVE-2026-6692

The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_fi…

Mitigation only
Fix from $1,950 2026-05-07
Unclassified HIGH 8.6
CVE-2026-41587

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From ve…

Patch available
Fix from $1,950 2026-05-07
Unclassified HIGH 8.8
CVE-2026-41938

Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with medi…

Patch available
Fix from $1,950 2026-05-06
Unclassified HIGH 8.8
CVE-2026-6261

The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() func…

Mitigation only
Fix from $1,950 2026-05-05
Openstamanager HIGH 7.2
CVE-2026-38751

OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upl…

Fix: after 2.10
Fix from $1,950 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7733

A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/common/service/UploadService.…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7732

A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.ph…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7711

A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wra…

Mitigation only
Fix from $1,950 2026-05-04
Unclassified MEDIUM 6.3
CVE-2026-7696

A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function …

Mitigation only
Fix from $1,600 2026-05-03
Ehrd Cpas HIGH 7.2
CVE-2026-7490

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified CRITICAL 9.8
CVE-2026-4882

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_A…

Mitigation only
Fix from $2,300 2026-05-02
Unclassified CRITICAL 9.8
CVE-2022-50993

Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpo…

Mitigation only
Fix from $2,300 2026-04-30
Unclassified HIGH 8.8
CVE-2026-38991

Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filena…

Mitigation only
Fix from $1,950 2026-04-29
Unclassified MEDIUM 6.3
CVE-2026-7107

A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This…

Mitigation only
Fix from $1,600 2026-04-27
Unclassified MEDIUM 6.3
CVE-2026-7044

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulati…

Mitigation only
Fix from $1,600 2026-04-26