Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-72592
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on …
No fix yet
CRITICAL 9.8
CVE-2026-19089
The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left …
No fix yet
HIGH 8.8
CVE-2026-16985
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-…
No fix yet
MEDIUM 6.3
CVE-2026-19210
A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?ac…
No fix yet
CRITICAL 9.8
CVE-2022-4995
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arb…
No fix yet
MEDIUM 5.3
CVE-2026-71434
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upl…
No fix yet
CRITICAL 9.8
CVE-2026-70558
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit…
No fix yet
CRITICAL 9.8
CVE-2026-67688
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke…
No fix yet
CRITICAL 9.1
CVE-2026-3418
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be …
No fix yet
MEDIUM 6.3
CVE-2026-19065
A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of t…
No fix yet
CRITICAL 10.0
CVE-2026-66665
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
No fix yet
HIGH 7.3
CVE-2026-18969
A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the fi…
No fix yet
MEDIUM 6.3
CVE-2026-18927
A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057…
No fix yet
HIGH 7.2
CVE-2026-18933
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_ca…
No fix yet
HIGH 8.8
CVE-2026-6147
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functi…
No fix yet
HIGH 7.2
CVE-2026-54416
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php',…
No fix yet
HIGH 8.1
CVE-2026-14553
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the or…
No fix yet
HIGH 8.5
CVE-2026-65986
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability tha…
No fix yet
HIGH 7.3
CVE-2026-18788
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager…
No fix yet
CRITICAL 9.8
CVE-2026-14175
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources all…
No fix yet
HIGH 7.2
CVE-2026-67243
freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative pri…
No fix yet
MEDIUM 6.5
CVE-2026-16548
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate …
No fix yet
CRITICAL 9.8
CVE-2026-16618
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file…
No fix yet
HIGH 7.2
CVE-2026-61524
WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated admin…
No fix yet
HIGH 7.2
CVE-2026-39931
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators wit…
No fix yet
CRITICAL 9.8
CVE-2026-16060
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, re…
No fix yet
CRITICAL 9.8
CVE-2026-16250
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi…
No fix yet
CRITICAL 9.8
CVE-2026-12872
The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authenticatio…
No fix yet
HIGH 7.2
CVE-2026-13157
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test…
No fix yet
HIGH 7.2
CVE-2026-13158
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type t…
No fix yet