Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2026-3535 The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownl… Mitigation only Fix from $2,3002026-04-08 HIGH 7.2 CVE-2026-33273 Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary fi… Matcha Invoice after 2.6.6 Fix from $1,9502026-04-08 CRITICAL 9.1 CVE-2026-35573 ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allo… Churchcrm 6.5.3+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-0740EPSS 63% The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Co… Mitigation only Fix from $2,3002026-04-07 HIGH 7.2 CVE-2026-35174 Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows… Chyrp Lite 2026.01+ Fix from $1,9502026-04-06 CRITICAL 9.8 CVE-2026-35047 Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitr… Bravecms 2.0.6+ Fix from $2,3002026-04-06 HIGH 8.8 CVE-2026-35164 Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found i… Bravecms 2.0.6+ Fix from $1,9502026-04-06 MEDIUM 6.3 CVE-2026-5670 A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move… Mitigation only Fix from $1,6002026-04-06 MEDIUM 5.5 CVE-2026-5704 A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu… Hardened Images No fix yet Fix from $1,6002026-04-06 HIGH 8.8 CVE-2019-25673 UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload mal… No fix yet Fix from $1,9502026-04-05 CRITICAL 9.8 CVE-2026-5573 A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipul… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05 MEDIUM 6.3 CVE-2026-5546 A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/mode… Mitigation only Fix from $1,6002026-04-05 CRITICAL 9.8 CVE-2016-20052 Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP execut… Snews after 1.7 Fix from $2,3002026-04-04 MEDIUM 5.3 CVE-2025-14938 The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "li… Mitigation only Fix from $1,6002026-04-04 MEDIUM 6.3 CVE-2026-5472 A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unkn… No fix yet Fix from $1,6002026-04-03 HIGH 8.8 CVE-2025-59710 An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During th… Biztalk360 11.6.3963.2611+ Fix from $1,9502026-04-03 HIGH 8.7 CVE-2026-34735 The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. In version 1.2.0 and prior, the quickUpload() endpoint… Mitigation only Fix from $1,9502026-04-02 HIGH 8.8 CVE-2026-2701EPSS 57% Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. Sharefile Storage Zones Controller 5.12.4+ Fix from $1,9502026-04-02 MEDIUM 6.3 CVE-2026-1879 A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of t… Mitigation only Fix from $1,6002026-04-01 HIGH 7.3 CVE-2026-5261 A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base… Mitigation only Fix from $1,9502026-04-01 MEDIUM 5.3 CVE-2026-30280 An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite c… Video Player No fix yet Fix from $1,6002026-03-31 MEDIUM 6.3 CVE-2026-5181 A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file … Mitigation only Fix from $1,6002026-03-31 HIGH 7.2 CVE-2025-32957 baserCMS is a website development framework. Prior to version 5.2.3, the application's restore function allows users to upload a .zip file, which is … Basercms 5.2.3+ Fix from $1,9502026-03-31 HIGH 7.3 CVE-2026-5001 A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is the function do_POST of the f… Mitigation only Fix from $1,9502026-03-28 HIGH 8.8 CVE-2026-25099 Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can … Bludit 3.18.4+ Fix from $1,9502026-03-27 HIGH 8.8 CVE-2026-33687 Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint … Sharp 9.20.0+ Fix from $1,9502026-03-26 CRITICAL 9.8 CVE-2025-55267 HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont… Aftermarket Cloud Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-4809 plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a cli… Mitigation only Fix from $2,3002026-03-26 MEDIUM 5.6 CVE-2026-4830 A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php … Mitigation only Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2026-33809 A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or a… Tiff 0.38.0+ Fix from $1,6002026-03-25