Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2023-53942 File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web s… File Thingie No fix yet Fix from $1,9502025-12-18 HIGH 8.8 CVE-2019-25229 An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types… Xperience after 12.0.29 Fix from $1,9502025-12-18 HIGH 8.8 CVE-2025-14885 A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the compon… Client Database Management System No fix yet Fix from $1,9502025-12-18 CRITICAL 9.0 CVE-2025-66074 Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webho… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.9 CVE-2025-64374 Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors:… Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.9 CVE-2025-64231 Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordp… Mitigation only Fix from $2,3002025-12-18 HIGH 8.8 CVE-2023-53933 Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extensi… Serendipity No fix yet Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2023-53921 SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. … Sitemagic Cms Mitigation only Fix from $2,3002025-12-17 CRITICAL 9.8 CVE-2023-53922 TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload … Tinywebgallery Mitigation only Fix from $2,3002025-12-17 HIGH 8.8 CVE-2023-53924 UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar exten… Ulicms No fix yet Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-68109 ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 CRITICAL 9.9 CVE-2025-67164 An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary c… Pagekit Mitigation only Fix from $2,3002025-12-17 HIGH 8.8 CVE-2025-66449 ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary f… Convertx 0.16.0+ Fix from $1,9502025-12-16 HIGH 7.2 CVE-2023-53889 Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the asset… Perch No fix yet Fix from $1,9502025-12-15 HIGH 7.2 CVE-2023-53892 Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jq… Blackcat Cms No fix yet Fix from $1,9502025-12-15 HIGH 7.2 CVE-2023-53885 Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP files with system command executi… Webutler No fix yet Fix from $1,9502025-12-15 MEDIUM 5.4 CVE-2023-53876 Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting p… Academy Lms No fix yet Fix from $1,6002025-12-15 HIGH 8.8 CVE-2023-53868 Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through th… Coppermine Photo Gallery No fix yet Fix from $1,9502025-12-15 HIGH 8.7 CVE-2023-53869 WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the med… No fix yet Fix from $1,9502025-12-15 CRITICAL 9.8 CVE-2023-53871 Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. At… Soosyze Mitigation only Fix from $2,3002025-12-15 HIGH 8.3 CVE-2024-44599 FNT Command 13.4.0 is vulnerable to Directory Traversal. Fnt Command 13.4.1+ Fix from $1,9502025-12-15 HIGH 8.8 CVE-2024-44598 FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. Fnt Command 13.4.1+ Fix from $1,9502025-12-15 HIGH 7.2 CVE-2025-14642 A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. … Computer Laboratory System No fix yet Fix from $1,9502025-12-14 HIGH 7.2 CVE-2025-14641 A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. Th… Computer Laboratory System No fix yet Fix from $1,9502025-12-14 HIGH 8.8 CVE-2025-13094 The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_fi… Mitigation only Fix from $1,9502025-12-13 CRITICAL 9.8 CVE-2025-14583 A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing … Online Student Enrollment System Mitigation only Fix from $2,3002025-12-12 HIGH 7.2 CVE-2025-14582 A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=us… Online Student Enrollment System No fix yet Fix from $1,9502025-12-12 HIGH 8.8 CVE-2025-12968 The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all ver… Mitigation only Fix from $1,9502025-12-12 HIGH 8.8 CVE-2025-34506 WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules… Wbce Cms after 1.6.3 Fix from $1,9502025-12-11 HIGH 7.2 CVE-2024-58313 xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execut… Xbtitfm No fix yet Fix from $1,9502025-12-11