Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.9
CVE-2025-68553
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affect…
Mitigation only
CRITICAL 9.9
CVE-2025-68554
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarc…
Mitigation only
HIGH 8.1
CVE-2026-28289EPSS 31%
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.2…
Freescout
1.8.207+
HIGH 8.0
CVE-2021-35485
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-sid…
Impact
after 19.11.2.10-20210118042150283
HIGH 7.2
CVE-2026-2269
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Fo…
Mitigation only
CRITICAL 9.8
CVE-2025-14532
DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which c…
Dorbycms
after 5.0
HIGH 7.2
CVE-2026-28270
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files wit…
Kiteworks
9.2.0+
HIGH 8.8
CVE-2026-27947
Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticat…
Group Office
6.8.154 / 25.0.87+
HIGH 8.7
CVE-2026-28274
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (X…
Initiative
0.32.2+
HIGH 8.8
CVE-2026-1565
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitra…
Mitigation only
HIGH 8.8
CVE-2026-26984
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …
Loris
26.0.5 / 27.0.2+
CRITICAL 9.6
CVE-2025-69771
Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execut…
Asbplayer
after 1.13.0
CRITICAL 9.8
CVE-2026-3187
A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api…
Sz Boot Parent
after 0.9.0
HIGH 8.8
CVE-2026-27636
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list…
Freescout
1.8.206+
HIGH 7.2
CVE-2026-22766
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged at…
Wyse Management Suite
5.5+
CRITICAL 9.8
CVE-2026-3025
A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of th…
Smart Heating Integrated Management Platform
Mitigation only
HIGH 8.7
CVE-2026-25648
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary Java…
Traccar
No fix yet
HIGH 8.8
CVE-2026-2979
A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/modu…
Fastapiadmin
after 2.2.0
HIGH 8.8
CVE-2026-2977
A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/m…
Fastapiadmin
after 2.2.0
HIGH 8.8
CVE-2026-2978
A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api…
Fastapiadmin
after 2.2.0
MEDIUM 6.5
CVE-2026-2976
A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v…
Fastapiadmin
after 2.2.0
HIGH 8.8
CVE-2018-25158
Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfind…
No fix yet
HIGH 8.8
CVE-2026-26746
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files…
Open Source Point Of Sale
No fix yet
CRITICAL 9.9
CVE-2025-69403
Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue af…
Mitigation only
CRITICAL 9.9
CVE-2025-68549
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affe…
Mitigation only
HIGH 8.8
CVE-2026-26975
Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow un…
Music Assistant Server
2.7.0+
HIGH 7.2
CVE-2025-13590
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST A…
Api Control Plane
Mitigation only
CRITICAL 9.8
CVE-2026-1405
The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image…
Mitigation only
MEDIUM 5.3
CVE-2025-12500
The Checkout Field Manager (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to unauthenticated limited file upload in all versio…
Mitigation only
CRITICAL 9.8
CVE-2026-2684
A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function o…
Electronic Archives System
after 3.2.210802