Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2026-1756 The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::f… Mitigation only Fix from $1,9502026-02-04 CRITICAL 9.8 CVE-2026-1813 A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp… Bolo Solo after 2.6.4 Fix from $2,3002026-02-04 HIGH 7.2 CVE-2020-37084 School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile phot… School Erp Pro No fix yet Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-25510 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.28.5.0+ Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2020-37090 School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upl… School Erp Pro Mitigation only Fix from $2,3002026-02-03 HIGH 8.8 CVE-2020-37073 Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the … Victor Cms No fix yet Fix from $1,9502026-02-03 MEDIUM 5.3 CVE-2026-24673 The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypa… Open Eclass Platform 4.2+ Fix from $1,6002026-02-03 MEDIUM 6.1 CVE-2025-70849 Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoin… Podinfo after 6.9.0 Fix from $1,6002026-02-03 CRITICAL 9.8 CVE-2025-69981 FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow… Fuxa Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-65875 An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a… Fpdf Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-61506 An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpo… Mediacrush after 1.0.1 Fix from $2,3002026-02-03 HIGH 8.8 CVE-2020-37113 GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP… Open Eclass Platform No fix yet Fix from $1,9502026-02-03 HIGH 8.8 CVE-2026-1730 The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin:… Mitigation only Fix from $1,9502026-02-03 HIGH 7.2 CVE-2026-1065 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due … Mitigation only Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2025-66480 Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component re… Im Server 1.4.3+ Fix from $2,3002026-02-02 HIGH 8.8 CVE-2026-25201 An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects M… Magicinfo 9 Server 21.1090.1+ Fix from $1,9502026-02-02 CRITICAL 9.8 CVE-2026-25200 A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in … Magicinfo 9 Server 21.1090.1+ Fix from $2,3002026-02-02 HIGH 7.2 CVE-2026-1742 A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cg… A8004t Firmware Mitigation only Fix from $1,9502026-02-02 HIGH 8.8 CVE-2020-37023 Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming maliciou… No fix yet Fix from $1,9502026-01-30 CRITICAL 10.0 CVE-2026-24729 An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allow… Mitigation only Fix from $2,3002026-01-30 HIGH 8.8 CVE-2020-37009 MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP fil… No fix yet Fix from $1,9502026-01-29 HIGH 8.8 CVE-2026-24897 Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files… Erugo after 0.2.14 Fix from $1,9502026-01-28 CRITICAL 9.0 CVE-2026-24769 NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in Noco… Nocodb 0.301.0+ Fix from $2,3002026-01-28 CRITICAL 9.1 CVE-2025-57794 Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The applica… Blue 8.14.9+ Fix from $2,3002026-01-28 CRITICAL 9.9 CVE-2025-57795 Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configur… Blue 8.14.13+ Fix from $2,3002026-01-28 MEDIUM 6.5 CVE-2020-36973 PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary … No fix yet Fix from $1,6002026-01-28 HIGH 7.2 CVE-2026-1400 The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… Mitigation only Fix from $1,9502026-01-28 CRITICAL 9.8 CVE-2025-69559 code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. Computer Book Store Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69565 code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 HIGH 8.8 CVE-2020-36942 Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload fe… Victor Cms No fix yet Fix from $1,9502026-01-27