Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.3 CVE-2026-2665 A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file Sys… Mitigation only Fix from $1,6002026-02-18 HIGH 7.2 CVE-2026-2666 A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Tem… Mcms No fix yet Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-70151 code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoi… Scholars Tracking System No fix yet Fix from $1,9502026-02-18 HIGH 8.8 CVE-2025-13689 IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to u… Datastage On Cloud Pak For Data 5.3.1+ Fix from $1,9502026-02-17 CRITICAL 9.8 CVE-2026-2550 A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipul… Mitigation only Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-1306 The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJ… Mitigation only Fix from $2,3002026-02-14 CRITICAL 9.8 CVE-2026-1358 Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could al… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2025-14014 Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Lt… Mitigation only Fix from $2,3002026-02-12 HIGH 8.8 CVE-2024-50620 Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce bef… Cipace 9.17+ Fix from $1,9502026-02-11 HIGH 7.5 CVE-2026-1458 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under … GitLab 18.6.6 / 18.7.4+ Fix from $1,9502026-02-11 CRITICAL 9.8 CVE-2026-1357EPSS 33% The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions u… Mitigation only Fix from $2,3002026-02-11 HIGH 8.8 CVE-2026-2097 Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell b… Agentflow Mitigation only Fix from $1,9502026-02-10 CRITICAL 9.1 CVE-2026-25923 my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application f… My Little Forum 20260208.1+ Fix from $2,3002026-02-09 HIGH 8.8 CVE-2025-10465 Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload … Mitigation only Fix from $1,9502026-02-09 HIGH 7.2 CVE-2026-2226 A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File … Douphp after 1.9 Fix from $1,9502026-02-09 HIGH 7.2 CVE-2026-2213 A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Adminis… Online Music Site No fix yet Fix from $1,9502026-02-09 CRITICAL 9.8 CVE-2026-2183 A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This aff… Certificate after 2017-10-16 Fix from $2,3002026-02-08 CRITICAL 9.8 CVE-2026-2164 A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/pr… E Commerce Mitigation only Fix from $2,3002026-02-08 HIGH 8.8 CVE-2026-2146 A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar… Yshopmall after 1.9.1 Fix from $1,9502026-02-08 CRITICAL 9.8 CVE-2026-2133 A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCate… Online Music Site Mitigation only Fix from $2,3002026-02-08 CRITICAL 9.8 CVE-2026-2113 A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/web… Tpadmin after 1.3.12 Fix from $2,3002026-02-07 HIGH 8.8 CVE-2025-69906 Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extens… Monstra Cms No fix yet Fix from $1,9502026-02-05 HIGH 8.8 CVE-2020-37117 jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbit… Jizhicms No fix yet Fix from $1,9502026-02-05 HIGH 8.8 CVE-2026-25056 n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed a… N8n 1.118.0 / 2.4.0+ Fix from $1,9502026-02-04 HIGH 8.8 CVE-2026-20098 A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary f… Meeting Management 3.12.1+ Fix from $1,9502026-02-04 MEDIUM 6.5 CVE-2026-23704 A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on… Mitigation only Fix from $1,6002026-02-04 HIGH 8.8 CVE-2026-1756 The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::f… Mitigation only Fix from $1,9502026-02-04 CRITICAL 9.8 CVE-2026-1813 A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp… Bolo Solo after 2.6.4 Fix from $2,3002026-02-04 HIGH 7.2 CVE-2020-37084 School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile phot… School Erp Pro No fix yet Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-25510 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.28.5.0+ Fix from $1,9502026-02-03