Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.3 CVE-2012-10064 Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-co… No fix yet Fix from $2,3002026-01-16 HIGH 8.8 CVE-2026-21625 User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type… Easydiscuss after 5.0.15 Fix from $1,9502026-01-16 CRITICAL 9.8 CVE-2025-14894 Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME val… Filemanager 1.0.0+ Fix from $2,3002026-01-16 HIGH 8.8 CVE-2025-12957 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to … Mitigation only Fix from $1,9502026-01-16 CRITICAL 9.8 CVE-2026-1021 Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload a… Police Statistics Database System after 1.0.2 Fix from $2,3002026-01-16 HIGH 8.8 CVE-2021-47788 WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbi… Websitebaker No fix yet Fix from $1,9502026-01-16 MEDIUM 5.4 CVE-2021-47783 Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attac… Phpwcms No fix yet Fix from $1,6002026-01-16 CRITICAL 9.3 CVE-2011-10041 Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file … Mitigation only Fix from $2,3002026-01-15 HIGH 8.8 CVE-2025-67077 File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the Uploa… Agora Project 25.10+ Fix from $1,9502026-01-15 CRITICAL 9.8 CVE-2025-67079 File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library vi… Agora Project 25.10+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47819 ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code exe… Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47753 phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file… Cms Mitigation only Fix from $2,3002026-01-15 HIGH 8.8 CVE-2021-47757 Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authe… Patient Management System No fix yet Fix from $1,9502026-01-15 HIGH 8.8 CVE-2021-47758 Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP … Patient Management System No fix yet Fix from $1,9502026-01-15 HIGH 8.8 CVE-2025-13062 The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to ins… Mitigation only Fix from $1,9502026-01-15 HIGH 7.2 CVE-2022-50939 e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files thro… E107 No fix yet Fix from $1,9502026-01-13 HIGH 8.8 CVE-2022-50936 WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the a… Wbce Cms No fix yet Fix from $1,9502026-01-13 HIGH 7.2 CVE-2022-50916 e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manag… E107 No fix yet Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2022-50912 ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. A… Impresscms Mitigation only Fix from $2,3002026-01-13 HIGH 7.2 CVE-2022-50907 e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute … E107 No fix yet Fix from $1,9502026-01-13 HIGH 8.8 CVE-2022-50898 NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenti… Nanocms No fix yet Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2022-50893 VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload … Wallpaper Admin Mitigation only Fix from $2,3002026-01-13 HIGH 7.2 CVE-2025-37175 Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating syst… Arubaos 8.10.0.21 / 8.13.1.1+ Fix from $1,9502026-01-13 MEDIUM 5.3 CVE-2025-62182 Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could… Mitigation only Fix from $1,6002026-01-13 CRITICAL 9.8 CVE-2025-65783 An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to … Hub Mitigation only Fix from $2,3002026-01-13 MEDIUM 6.6 CVE-2026-0496 SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper… Mitigation only Fix from $1,6002026-01-13 HIGH 7.2 CVE-2026-22786 Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint res… Gin Vue Admin after 2.8.7 Fix from $1,9502026-01-12 HIGH 8.8 CVE-2026-22789 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validatio… Wem Patch available Fix from $1,9502026-01-12 HIGH 8.8 CVE-2026-22799 Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file upl… Emlog 2.6.1+ Fix from $1,9502026-01-12 CRITICAL 9.8 CVE-2025-66802 Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into … Covid 19 Contact Tracing System Mitigation only Fix from $2,3002026-01-12