Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2026-72592 An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on … No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-19089 The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left … No fix yet Fix from $5,7502026-08-10 HIGH 8.8 CVE-2026-16985 The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.3 CVE-2026-19210 A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?ac… No fix yet Fix from $1,6002026-08-07 CRITICAL 9.8 CVE-2022-4995 Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arb… No fix yet Fix from $2,3002026-08-07 MEDIUM 5.3 CVE-2026-71434 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upl… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-70558 Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67688 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-3418 The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be … No fix yet Fix from $2,3002026-08-06 MEDIUM 6.3 CVE-2026-19065 A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of t… No fix yet Fix from $1,6002026-08-06 CRITICAL 10.0 CVE-2026-66665 Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. No fix yet Fix from $2,3002026-08-06 HIGH 7.3 CVE-2026-18969 A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the fi… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-18927 A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057… No fix yet Fix from $1,6002026-08-05 HIGH 7.2 CVE-2026-18933 The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_ca… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functi… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-54416 Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php',… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-14553 The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the or… No fix yet Fix from $1,9502026-08-05 HIGH 8.5 CVE-2026-65986 CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability tha… No fix yet Fix from $1,9502026-08-04 HIGH 7.3 CVE-2026-18788 A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager… No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-14175 Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources all… No fix yet Fix from $2,3002026-08-04 HIGH 7.2 CVE-2026-67243 freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative pri… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.5 CVE-2026-16548 The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate … No fix yet Fix from $1,6002026-08-04 CRITICAL 9.8 CVE-2026-16618 The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file… No fix yet Fix from $2,3002026-08-04 HIGH 7.2 CVE-2026-61524 WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated admin… No fix yet Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-39931 OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators wit… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-16060 The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, re… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-16250 The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-12872 The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authenticatio… No fix yet Fix from $2,3002026-08-03 HIGH 7.2 CVE-2026-13157 The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test… No fix yet Fix from $1,9502026-08-01 HIGH 7.2 CVE-2026-13158 The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type t… No fix yet Fix from $1,9502026-08-01