Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.3 CVE-2026-7043 A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. T… Mitigation only Fix from $1,6002026-04-26 HIGH 8.1 CVE-2026-5364 The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3.… Mitigation only Fix from $1,9502026-04-24 HIGH 8.8 CVE-2026-41269 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload setti… Flowise 3.1.0+ Fix from $1,9502026-04-23 CRITICAL 9.8 CVE-2026-6885 Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated rem… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-3844EPSS 37% The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote'… Mitigation only Fix from $2,3002026-04-23 HIGH 7.2 CVE-2025-36074 IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not v… Security Verify Directory after 10.0.3 Fix from $1,9502026-04-23 MEDIUM 6.1 CVE-2026-6835 The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any… Mitigation only Fix from $1,6002026-04-22 CRITICAL 9.3 CVE-2019-25714 Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to… Mitigation only Fix from $2,3002026-04-21 HIGH 7.2 CVE-2026-37748 Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The … Visitor Management System No fix yet Fix from $1,9502026-04-21 CRITICAL 9.1 CVE-2026-6257 Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file … Patch available Fix from $2,3002026-04-20 HIGH 8.8 CVE-2026-6249 Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated attackers to execute arbitrary… Patch available Fix from $1,9502026-04-20 HIGH 8.8 CVE-2026-40488 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo… Magento 20.17.0+ Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6602 A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the… Mitigation only Fix from $1,9502026-04-20 HIGH 7.3 CVE-2026-6596 A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/b… Mitigation only Fix from $1,9502026-04-20 HIGH 8.8 CVE-2026-6518 The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in al… Mitigation only Fix from $1,9502026-04-18 CRITICAL 9.0 CVE-2026-40487 Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitr… Postiz 2.21.6+ Fix from $2,3002026-04-18 CRITICAL 9.1 CVE-2026-40484 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive… Patch available Fix from $2,3002026-04-18 HIGH 8.1 CVE-2026-5718 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and includin… Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.3 CVE-2026-6489 A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of th… Mitigation only Fix from $1,6002026-04-17 HIGH 8.7 CVE-2026-40262 Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies… Patch available Fix from $1,9502026-04-17 HIGH 8.0 CVE-2026-33435 Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which cou… Weblate 5.17+ Fix from $1,9502026-04-15 CRITICAL 9.8 CVE-2026-1555 The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all v… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.9 CVE-2026-38526 An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute ar… Mitigation only Fix from $2,3002026-04-14 HIGH 8.8 CVE-2026-40040 Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffecti… Mitigation only Fix from $1,9502026-04-13 HIGH 7.2 CVE-2026-30804 Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 … Pandora Fms 800.1+ Fix from $1,9502026-04-13 HIGH 8.4 CVE-2018-25258 RGui 3.5.0 contains a local buffer overflow vulnerability in the GUI preferences dialog that allows attackers to bypass DEP protections through struc… No fix yet Fix from $1,9502026-04-12 HIGH 8.8 CVE-2026-33704 Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on th… Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-32931 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload … Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10 CRITICAL 9.8 CVE-2026-2942 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadP… Mitigation only Fix from $2,3002026-04-08 HIGH 7.2 CVE-2026-4808 The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moveUpl… Mitigation only Fix from $1,9502026-04-08