Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 10.0 CVE-2026-24815 Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangt… Patch available Fix from $2,3002026-01-27 HIGH 7.2 CVE-2026-1424 A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation lea… News Portal No fix yet Fix from $1,9502026-01-26 CRITICAL 9.8 CVE-2026-1423 A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admi… Online Examination System Mitigation only Fix from $2,3002026-01-26 HIGH 7.5 CVE-2026-0911 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type… Mitigation only Fix from $1,9502026-01-24 CRITICAL 9.8 CVE-2025-13374 The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX a… Mitigation only Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2025-70457 A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The appli… Modern Image Gallery App Mitigation only Fix from $2,3002026-01-23 HIGH 8.8 CVE-2021-47904 PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a m… No fix yet Fix from $1,9502026-01-23 HIGH 8.8 CVE-2021-47888 Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP … No fix yet Fix from $1,9502026-01-23 CRITICAL 10.0 CVE-2025-69828 File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2025-69312 Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Upload a Web Shell to a Web … Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-68986 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects … Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-68909 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious Files.This issue affects Blog… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-68910 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious Files.This issue affects Blogzee:… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-67968 Unrestricted Upload of File with Dangerous Type vulnerability in InspiryThemes Real Homes CRM realhomes-crm allows Using Malicious Files.This issue a… Mitigation only Fix from $2,3002026-01-22 CRITICAL 10.0 CVE-2025-68001 Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a Web Shell to a Web Server.Thi… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-62050 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.… Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.9 CVE-2025-62056 Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <=… Mitigation only Fix from $2,3002026-01-22 CRITICAL 10.0 CVE-2025-50002 Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects … Mitigation only Fix from $2,3002026-01-22 HIGH 8.1 CVE-2025-10856 Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This i… Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2026-1331 MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execu… Meetinghub Paperless Meetings 2025-12-10+ Fix from $2,3002026-01-22 MEDIUM 5.4 CVE-2026-24034 Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be tr… Horilla 1.5.0+ Fix from $1,6002026-01-22 HIGH 8.0 CVE-2026-24010 Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Soci… Horilla 1.5.0+ Fix from $1,9502026-01-22 MEDIUM 5.4 CVE-2026-23499 Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff … Saleor 3.20.108 / 3.21.43+ Fix from $1,6002026-01-21 HIGH 8.8 CVE-2025-33015 IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Concert 2.2.0+ Fix from $1,9502026-01-20 HIGH 7.2 CVE-2026-1222 PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upl… Mitigation only Fix from $1,9502026-01-20 CRITICAL 9.8 CVE-2025-55251 HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code … Aion Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-1152 A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code … Mpay after 1.2.4 Fix from $2,3002026-01-19 MEDIUM 6.3 CVE-2026-1126 A security vulnerability has been detected in lwj flow up to a3d2fe8133db9d3b50fda4f66f68634640344641. This affects the function uploadFile of the fi… Mitigation only Fix from $1,6002026-01-18 CRITICAL 9.8 CVE-2026-1107 A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av… Eyoucms Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1061 A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/… Teamwork Management System after 2.28.0 Fix from $2,3002026-01-17