Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.9 CVE-2026-32536 Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious File… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-32523 Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJ… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.1 CVE-2026-32524 Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This iss… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-32482 Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-25413 Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affec… Mitigation only Fix from $2,3002026-03-25 HIGH 7.2 CVE-2026-23636 Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an … Kiteworks 9.2.1+ Fix from $1,9502026-03-25 HIGH 8.8 CVE-2019-25647 PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute ar… Phreebookserp No fix yet Fix from $1,9502026-03-24 HIGH 8.8 CVE-2019-25630 PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload mal… Phreebookserp No fix yet Fix from $1,9502026-03-24 HIGH 7.8 CVE-2019-25626 River Past Cam Do 3.7.6 contains a local buffer overflow vulnerability in the activation code input field that allows local attackers to execute arbi… River Past Cam Do after 3.7.6 Fix from $1,9502026-03-24 HIGH 7.8 CVE-2019-25627 FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by trigger… Flexhex No fix yet Fix from $1,9502026-03-24 HIGH 8.8 CVE-2026-3533 The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as we… Mitigation only Fix from $1,9502026-03-24 HIGH 8.8 CVE-2025-60947 Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code exec… Csweb Patch available Fix from $1,9502026-03-23 HIGH 8.8 CVE-2026-33717 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoE… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 8.8 CVE-2026-33647 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file con… Avideo after 26.0 Fix from $1,9502026-03-23 MEDIUM 6.3 CVE-2026-4586 A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-… Mitigation only Fix from $1,6002026-03-23 MEDIUM 5.3 CVE-2026-1969 The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upl… Mitigation only Fix from $1,6002026-03-23 MEDIUM 6.2 CVE-2019-25616 AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized stri… No fix yet Fix from $1,6002026-03-22 HIGH 7.3 CVE-2026-4536 A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulati… Mitigation only Fix from $1,9502026-03-22 HIGH 8.2 CVE-2019-25580 ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code… Owndms after 4.7 Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2019-25582 i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating th… I Doit No fix yet Fix from $1,6002026-03-21 MEDIUM 6.3 CVE-2026-4505 A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages… Mitigation only Fix from $1,6002026-03-20 HIGH 8.8 CVE-2026-32989 Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafte… Intranet Portal No fix yet Fix from $1,9502026-03-20 HIGH 8.8 CVE-2025-67260 The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow atta… Terrapack Tkservercgi Mitigation only Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-33071 FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension includi… Filerise 3.8.0+ Fix from $1,9502026-03-20 CRITICAL 9.8 CVE-2026-32985 Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality t… Xerte Online Toolkits after 3.14.0 Fix from $2,3002026-03-20 HIGH 8.8 CVE-2026-32756 Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documen… Admidio 5.0.7+ Fix from $1,9502026-03-20 HIGH 7.2 CVE-2026-27043 Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/… Mitigation only Fix from $1,9502026-03-19 CRITICAL 9.1 CVE-2026-27067 Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.0 CVE-2026-27540 Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-29859 An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file. Aapanel Mitigation only Fix from $2,3002026-03-18