Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.9 CVE-2025-68562 Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG… Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2024-27480 givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload. Vvvebjs No fix yet Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2024-25182 givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php. Vvvebjs Mitigation only Fix from $2,3002025-12-29 HIGH 8.8 CVE-2025-15199 A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboar… College Notes Uploading System Mitigation only Fix from $1,9502025-12-29 HIGH 8.8 CVE-2025-55061 CWE-434 Unrestricted Upload of File with Dangerous Type No fix yet Fix from $1,9502025-12-29 HIGH 7.2 CVE-2025-15197 A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown co… News Buzz No fix yet Fix from $1,9502025-12-29 CRITICAL 9.8 CVE-2025-57460 File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell. Machpanel Mitigation only Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15228 BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and exe… Bpmflowwebkit 5.0.5+ Fix from $2,3002025-12-29 CRITICAL 9.8 CVE-2025-15226 WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdo… Wmpro after 5.2 Fix from $2,3002025-12-29 CRITICAL 10.0 CVE-2025-52691 KEVEPSS 85% Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, po… Smartermail 100.0.9413+ Fix from $2,3002025-12-29 HIGH 7.7 CVE-2025-15067 Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server.This issue affects Inno… Mitigation only Fix from $1,9502025-12-29 MEDIUM 6.3 CVE-2025-15152 A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduc… Mitigation only Fix from $1,6002025-12-28 HIGH 7.2 CVE-2025-15110 A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Upload of the file Admin/Home/C… Xcms No fix yet Fix from $1,9502025-12-27 HIGH 7.3 CVE-2025-15109 A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of the file Public/javascripts/a… Mitigation only Fix from $1,9502025-12-27 HIGH 8.8 CVE-2025-2155 Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclu… Mitigation only Fix from $1,9502025-12-24 HIGH 8.8 CVE-2025-15050 A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.p… Student File Management System No fix yet Fix from $1,9502025-12-24 CRITICAL 9.8 CVE-2025-51511 Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads. Cadmium Cms Mitigation only Fix from $2,3002025-12-23 CRITICAL 9.8 CVE-2023-53980 ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Att… Projectsend Mitigation only Fix from $2,3002025-12-22 HIGH 8.8 CVE-2023-53971 WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functi… Webtareas No fix yet Fix from $1,9502025-12-22 CRITICAL 10.0 CVE-2025-67288 An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this … Umbraco Cms Mitigation only Fix from $2,3002025-12-22 CRITICAL 9.6 CVE-2025-67289 An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploadin… Erpnext No fix yet Fix from $2,3002025-12-22 HIGH 8.8 CVE-2025-15009 A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/com… Chestnutcms after 1.5.8 Fix from $1,9502025-12-22 HIGH 8.1 CVE-2025-14800 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file… Mitigation only Fix from $1,9502025-12-21 CRITICAL 9.8 CVE-2025-13329 The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback fu… Mitigation only Fix from $2,3002025-12-20 CRITICAL 9.8 CVE-2023-53950 InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions throug… Mitigation only Fix from $2,3002025-12-19 HIGH 8.8 CVE-2023-53952 Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension… Dotclear No fix yet Fix from $1,9502025-12-19 HIGH 8.8 CVE-2023-53956 Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the fil… No fix yet Fix from $1,9502025-12-19 MEDIUM 5.3 CVE-2025-66908 Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR image upload functionality. T… Turms No fix yet Fix from $1,6002025-12-19 CRITICAL 9.1 CVE-2025-68398 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i… Weblate 5.15.1+ Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-14849 Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. Webaccess\/scada Mitigation only Fix from $2,3002025-12-18