Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2026-28673 xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the standard plugin… Xiaoheifs 0.4.0+ Fix from $1,9502026-03-18 HIGH 7.2 CVE-2026-28674 xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPl… Xiaoheifs 0.4.0+ Fix from $1,9502026-03-18 HIGH 7.3 CVE-2026-4220 A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the fil… Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4221 A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage o… Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4201 A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of … Mitigation only Fix from $1,9502026-03-16 HIGH 7.3 CVE-2026-4191 A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Pi… Mitigation only Fix from $1,9502026-03-16 CRITICAL 9.8 CVE-2017-20224 Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal… Sdt Cs3b1 Firmware Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-3891EPSS 25% The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation… Mitigation only Fix from $2,3002026-03-13 HIGH 8.8 CVE-2025-13067 The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is du… Mitigation only Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-3800 A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?… Resort Reservation System No fix yet Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3797 A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile o… Video Surveillance System Firmware Mitigation only Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3748 A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/… Bytedesk 1.4.5.1+ Fix from $1,9502026-03-08 HIGH 8.8 CVE-2026-3749 A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/jav… Bytedesk 1.4.5.1+ Fix from $1,9502026-03-08 CRITICAL 9.8 CVE-2026-29186 Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb… Backstage Plugin Techdocs Node 1.14.3+ Fix from $2,3002026-03-07 CRITICAL 9.8 CVE-2026-30821EPSS 15% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId… Flowise 3.0.13+ Fix from $2,3002026-03-07 HIGH 8.2 CVE-2018-25171 EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code thr… No fix yet Fix from $1,9502026-03-06 MEDIUM 6.5 CVE-2018-25162 2-Plan Team 1.0.4 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload executable PHP files by sending multi… No fix yet Fix from $1,6002026-03-06 HIGH 8.0 CVE-2026-28800 Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Discord Remote Control set up in a… Natro Macro 1.1.0+ Fix from $1,9502026-03-06 MEDIUM 5.4 CVE-2026-27605 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4… Chartbrew 4.8.4+ Fix from $1,6002026-03-06 HIGH 8.8 CVE-2026-28502 WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVi… Avideo 24.0+ Fix from $1,9502026-03-06 HIGH 8.8 CVE-2026-29041 Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability ca… Chamilo Lms 1.11.34+ Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability Devices Pricing Program No fix yet Fix from $2,3002026-03-05 HIGH 8.1 CVE-2026-3459 The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type va… Mitigation only Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-21628 A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution. Astroid Framework after 3.3.10 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-2743 Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf… Seppmail after 15.0.2.1 Fix from $2,3002026-03-05 HIGH 8.5 CVE-2026-28133 Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue a… Mitigation only Fix from $1,9502026-03-05 CRITICAL 9.1 CVE-2026-28114 Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2026-24960 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-23802 Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI En… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2025-68555 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affect… Mitigation only Fix from $2,3002026-03-05