Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.9 CVE-2025-68553 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affect… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2025-68554 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarc… Mitigation only Fix from $2,3002026-03-05 HIGH 8.1 CVE-2026-28289EPSS 31% FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.2… Freescout 1.8.207+ Fix from $1,9502026-03-03 HIGH 8.0 CVE-2021-35485 The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-sid… Impact after 19.11.2.10-20210118042150283 Fix from $1,9502026-03-03 HIGH 7.2 CVE-2026-2269 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Fo… Mitigation only Fix from $1,9502026-03-03 CRITICAL 9.8 CVE-2025-14532 DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which c… Dorbycms after 5.0 Fix from $2,3002026-03-02 HIGH 7.2 CVE-2026-28270 Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files wit… Kiteworks 9.2.0+ Fix from $1,9502026-02-27 HIGH 8.8 CVE-2026-27947 Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticat… Group Office 6.8.154 / 25.0.87+ Fix from $1,9502026-02-27 HIGH 8.7 CVE-2026-28274 Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (X… Initiative 0.32.2+ Fix from $1,9502026-02-26 HIGH 8.8 CVE-2026-1565 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitra… Mitigation only Fix from $1,9502026-02-26 HIGH 8.8 CVE-2026-26984 LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging … Loris 26.0.5 / 27.0.2+ Fix from $1,9502026-02-25 CRITICAL 9.6 CVE-2025-69771 Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execut… Asbplayer after 1.13.0 Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3187 A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api… Sz Boot Parent after 0.9.0 Fix from $2,3002026-02-25 HIGH 8.8 CVE-2026-27636 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list… Freescout 1.8.206+ Fix from $1,9502026-02-25 HIGH 7.2 CVE-2026-22766 Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged at… Wyse Management Suite 5.5+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2026-3025 A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of th… Smart Heating Integrated Management Platform Mitigation only Fix from $2,3002026-02-23 HIGH 8.7 CVE-2026-25648 Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary Java… Traccar No fix yet Fix from $1,9502026-02-23 HIGH 8.8 CVE-2026-2979 A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/modu… Fastapiadmin after 2.2.0 Fix from $1,9502026-02-23 HIGH 8.8 CVE-2026-2977 A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/m… Fastapiadmin after 2.2.0 Fix from $1,9502026-02-23 HIGH 8.8 CVE-2026-2978 A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api… Fastapiadmin after 2.2.0 Fix from $1,9502026-02-23 MEDIUM 6.5 CVE-2026-2976 A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v… Fastapiadmin after 2.2.0 Fix from $1,6002026-02-23 HIGH 8.8 CVE-2018-25158 Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfind… No fix yet Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-26746 OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files… Open Source Point Of Sale No fix yet Fix from $1,9502026-02-20 CRITICAL 9.9 CVE-2025-69403 Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue af… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.9 CVE-2025-68549 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affe… Mitigation only Fix from $2,3002026-02-20 HIGH 8.8 CVE-2026-26975 Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow un… Music Assistant Server 2.7.0+ Fix from $1,9502026-02-20 HIGH 7.2 CVE-2025-13590 A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A… Api Control Plane Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-1405 The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image… Mitigation only Fix from $2,3002026-02-19 MEDIUM 5.3 CVE-2025-12500 The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versio… Mitigation only Fix from $1,6002026-02-19 CRITICAL 9.8 CVE-2026-2684 A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function o… Electronic Archives System after 3.2.210802 Fix from $2,3002026-02-19