Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.1 CVE-2026-22783 Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS dat… Iris 2.4.24+ Fix from $1,9502026-01-12 HIGH 8.8 CVE-2025-46068 An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism Director Mitigation only Fix from $1,9502026-01-12 CRITICAL 9.8 CVE-2025-15503 A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function o… Operation And Maintenance Security Management System after 3.0.8 Fix from $2,3002026-01-10 HIGH 7.2 CVE-2025-15495 A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the… Simple Php Cms No fix yet Fix from $1,9502026-01-09 CRITICAL 9.8 CVE-2025-67325 Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote … Qloapps after 1.7.0 Fix from $2,3002026-01-08 HIGH 7.2 CVE-2026-22241 The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an arbitrary file upload vuln… Openeclass 4.1+ Fix from $1,9502026-01-08 CRITICAL 9.9 CVE-2025-67924 Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affe… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.1 CVE-2025-67910 Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.8 CVE-2019-25296 The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_uploa… Mitigation only Fix from $2,3002026-01-08 CRITICAL 9.9 CVE-2026-21877EPSS 5% n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code us… N8n 1.121.3+ Fix from $2,3002026-01-08 MEDIUM 6.8 CVE-2025-66837 A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware Aris after 10.0.23.0.3587512 Fix from $1,6002026-01-07 CRITICAL 9.8 CVE-2026-0643 A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=re… House Rental And Property Listing Project Mitigation only Fix from $2,3002026-01-07 HIGH 8.8 CVE-2025-15158 The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in the 'wpse_file_and_ext_webp' … Mitigation only Fix from $1,9502026-01-07 MEDIUM 6.1 CVE-2025-14842 The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all ve… Mitigation only Fix from $1,6002026-01-07 CRITICAL 9.9 CVE-2025-30996 Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Fol… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.1 CVE-2023-50897 Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media F… Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.9 CVE-2025-31048 Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: fr… Mitigation only Fix from $2,3002026-01-05 HIGH 8.8 CVE-2025-15240 QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers t… Qoca Aim 2.7.6+ Fix from $1,9502026-01-05 CRITICAL 9.8 CVE-2025-15448 A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the function Upload of the file src/m… Javamall Mitigation only Fix from $2,3002026-01-05 CRITICAL 9.8 CVE-2026-0577 A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file … Online Product Reservation System Mitigation only Fix from $2,3002026-01-04 CRITICAL 9.8 CVE-2026-0566 A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_po… Content Management System Mitigation only Fix from $2,3002026-01-02 HIGH 8.8 CVE-2026-0547 A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-stud… Online Course Registration after 3.1 Fix from $1,9502026-01-02 HIGH 7.3 CVE-2025-15426 A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/webuploader/0.1.5/server/previe… No fix yet Fix from $1,9502026-01-02 HIGH 8.8 CVE-2025-15423 A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Suc… Empirecms after 8.0 Fix from $1,9502026-01-02 MEDIUM 5.4 CVE-2025-15415 A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the… Wangmarket after 6.4 Fix from $1,6002026-01-01 HIGH 8.8 CVE-2025-15404 A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /s… School File Management System No fix yet Fix from $1,9502026-01-01 MEDIUM 5.6 CVE-2025-67706 ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker … Arcgis Server after 11.5 Fix from $1,6002025-12-31 MEDIUM 5.6 CVE-2025-67707 ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker … Arcgis Server after 11.5 Fix from $1,6002025-12-31 HIGH 7.2 CVE-2025-15360 A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/commo… Newbee Mall Plus No fix yet Fix from $1,9502025-12-30 HIGH 7.2 CVE-2025-15262 A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component S… Simple Php Cms No fix yet Fix from $1,9502025-12-30