Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.9 CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not incl… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-73996 Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.9 CVE-2026-66627 Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.9 CVE-2026-32474 Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.9 CVE-2026-32463 Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.6 CVE-2026-28192 Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. Fix unknown Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2024-14046 A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/contro… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.8 CVE-2026-15748 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl… Fix unknown Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-65640 WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisit… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-67678 File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50768 File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the … Fix unknown Fix from $5,7502026-08-17 HIGH 7.2 CVE-2026-16137 In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable uplo… Fix unknown Fix from $4,9002026-08-17 HIGH 8.8 CVE-2026-74845 Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers … Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-16098 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_han… No fix yet Fix from $5,7502026-08-16 HIGH 8.8 CVE-2026-14498 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' paramet… No fix yet Fix from $4,9002026-08-16 HIGH 8.7 CVE-2026-74767 Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from … No fix yet Fix from $4,9002026-08-15 HIGH 8.8 CVE-2026-18438 The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Cod… No fix yet Fix from $4,9002026-08-15 HIGH 8.8 CVE-2026-15965 The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t… No fix yet Fix from $4,9002026-08-15 HIGH 7.2 CVE-2026-66271 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil… Wyse Management Suite No fix yet Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-66270 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil… Wyse Management Suite No fix yet Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-49827 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u… No fix yet Fix from $5,7502026-08-13 MEDIUM 6.8 CVE-2026-65939 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within … No fix yet Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-18391 The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Orde… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.8 CVE-2026-15039 The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users t… No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-55676 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-13457 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-72762 n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72557 An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-24330 A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un… No fix yet Fix from $4,0002026-08-11