Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.9
CVE-2026-73373
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not incl…
Fix unknown
CRITICAL 9.8
CVE-2026-73996
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Fix unknown
CRITICAL 9.9
CVE-2026-66627
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Fix unknown
CRITICAL 9.9
CVE-2026-32474
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Fix unknown
CRITICAL 9.9
CVE-2026-32463
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Fix unknown
CRITICAL 9.6
CVE-2026-28192
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Fix unknown
MEDIUM 6.3
CVE-2024-14046
A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/contro…
Fix unknown
CRITICAL 9.8
CVE-2026-15748
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…
Fix unknown
HIGH 8.8
CVE-2026-65640
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.
Prerequisit…
Fix unknown
CRITICAL 9.8
CVE-2026-67678
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
Fix unknown
CRITICAL 9.8
CVE-2026-50768
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the …
Fix unknown
HIGH 7.2
CVE-2026-16137
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable uplo…
Fix unknown
HIGH 8.8
CVE-2026-74845
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers …
Fix unknown
CRITICAL 9.8
CVE-2026-16098
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_han…
No fix yet
HIGH 8.8
CVE-2026-14498
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' paramet…
No fix yet
HIGH 8.7
CVE-2026-74767
Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from …
No fix yet
HIGH 8.8
CVE-2026-18438
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Cod…
No fix yet
HIGH 8.8
CVE-2026-15965
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t…
No fix yet
HIGH 7.2
CVE-2026-66271
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…
Wyse Management Suite
No fix yet
HIGH 7.2
CVE-2026-66270
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…
Wyse Management Suite
No fix yet
MEDIUM 6.5
CVE-2026-58428
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
No fix yet
CRITICAL 9.8
CVE-2026-49827
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…
No fix yet
MEDIUM 6.8
CVE-2026-65939
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within …
No fix yet
CRITICAL 9.8
CVE-2026-18391
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Orde…
No fix yet
CRITICAL 9.8
CVE-2026-15039
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users t…
No fix yet
HIGH 8.8
CVE-2026-55676
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a…
No fix yet
HIGH 7.5
CVE-2026-13457
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including…
No fix yet
HIGH 7.7
CVE-2026-72762
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format…
No fix yet
HIGH 8.8
CVE-2026-72557
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via …
No fix yet
MEDIUM 6.5
CVE-2026-24330
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un…
No fix yet