Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-28673
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the standard plugin…
Xiaoheifs
0.4.0+
HIGH 7.2
CVE-2026-28674
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPl…
Xiaoheifs
0.4.0+
HIGH 7.3
CVE-2026-4220
A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the fil…
Mitigation only
HIGH 7.3
CVE-2026-4221
A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage o…
Mitigation only
HIGH 7.3
CVE-2026-4201
A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of …
Mitigation only
HIGH 7.3
CVE-2026-4191
A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Pi…
Mitigation only
CRITICAL 9.8
CVE-2017-20224
Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal…
Sdt Cs3b1 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-3891EPSS 25%
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation…
Mitigation only
HIGH 8.8
CVE-2025-13067
The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is du…
Mitigation only
HIGH 8.8
CVE-2026-3800
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?…
Resort Reservation System
No fix yet
HIGH 8.8
CVE-2026-3797
A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile o…
Video Surveillance System Firmware
Mitigation only
HIGH 8.8
CVE-2026-3748
A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/…
Bytedesk
1.4.5.1+
HIGH 8.8
CVE-2026-3749
A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/jav…
Bytedesk
1.4.5.1+
CRITICAL 9.8
CVE-2026-29186
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb…
Backstage Plugin Techdocs Node
1.14.3+
CRITICAL 9.8
CVE-2026-30821EPSS 15%
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId…
Flowise
3.0.13+
HIGH 8.2
CVE-2018-25171
EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code thr…
No fix yet
MEDIUM 6.5
CVE-2018-25162
2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executable PHP files by sending multi…
No fix yet
HIGH 8.0
CVE-2026-28800
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a…
Natro Macro
1.1.0+
MEDIUM 5.4
CVE-2026-27605
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4…
Chartbrew
4.8.4+
HIGH 8.8
CVE-2026-28502
WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVi…
Avideo
24.0+
HIGH 8.8
CVE-2026-29041
Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability ca…
Chamilo Lms
1.11.34+
CRITICAL 9.8
CVE-2026-21536
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Devices Pricing Program
No fix yet
HIGH 8.1
CVE-2026-3459
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type va…
Mitigation only
CRITICAL 9.8
CVE-2026-21628
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.
Astroid Framework
after 3.3.10
CRITICAL 9.8
CVE-2026-2743
Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf…
Seppmail
after 15.0.2.1
HIGH 8.5
CVE-2026-28133
Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue a…
Mitigation only
CRITICAL 9.1
CVE-2026-28114
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell …
Mitigation only
CRITICAL 9.9
CVE-2026-24960
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: …
Mitigation only
CRITICAL 9.1
CVE-2026-23802
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI En…
Mitigation only
CRITICAL 9.9
CVE-2025-68555
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affect…
Mitigation only