Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.2 CVE-2024-58298 Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicio… No fix yet Fix from $2,3002025-12-11 HIGH 8.6 CVE-2024-58295 ElkArte Forum 1.1.9 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the… No fix yet Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-14530 A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin… Real Estate Property Listing App No fix yet Fix from $1,9502025-12-11 CRITICAL 9.8 CVE-2025-65474 An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary c… Easyimages2.0 after 2.8.6 Fix from $2,3002025-12-11 HIGH 8.8 CVE-2025-65471 An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary c… Easyimages2.0 after 2.8.6 Fix from $1,9502025-12-11 CRITICAL 9.8 CVE-2025-14522 A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /… Hfly after 2016-05-11 Fix from $2,3002025-12-11 HIGH 7.2 CVE-2024-58282 Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the m… Serendipity No fix yet Fix from $1,9502025-12-10 HIGH 8.8 CVE-2024-58283 WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the E… Wbce Cms No fix yet Fix from $1,9502025-12-10 HIGH 8.8 CVE-2024-58279 appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files throug… Apprain No fix yet Fix from $1,9502025-12-10 HIGH 8.8 CVE-2024-58281 Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media uplo… Dotclear No fix yet Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2020-36897 QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to u… Qihang Media Web Digital Signage Mitigation only Fix from $2,3002025-12-10 HIGH 8.8 CVE-2025-14390 The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to missing or incorrect nonce va… Mitigation only Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2025-67506 PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/… Pipeshub Patch available Fix from $2,3002025-12-10 CRITICAL 9.1 CVE-2025-61808EPSS 10% ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could … Coldfusion Mitigation only Fix from $2,3002025-12-10 HIGH 8.8 CVE-2025-56704 LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An auth… Leptoncms No fix yet Fix from $1,9502025-12-09 HIGH 7.2 CVE-2025-14219 A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/a… Retro Basketball Shoes Online Store No fix yet Fix from $1,9502025-12-08 CRITICAL 9.8 CVE-2025-14199 A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text… Verysync after 2.21.3 Fix from $2,3002025-12-07 HIGH 8.8 CVE-2025-14195 A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/a… Employee Profile Management System No fix yet Fix from $1,9502025-12-07 HIGH 8.8 CVE-2025-13065EPSS 13% The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insuff… Mitigation only Fix from $1,9502025-12-06 HIGH 8.8 CVE-2025-12966 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the resolve_import_d… Mitigation only Fix from $1,9502025-12-06 CRITICAL 9.8 CVE-2025-12673 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() f… Mitigation only Fix from $2,3002025-12-06 HIGH 7.5 CVE-2020-36882 Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial o… Diskboss No fix yet Fix from $1,9502025-12-05 HIGH 8.8 CVE-2025-65897 zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file up… Zdh Web after 5.6.17 Fix from $1,9502025-12-05 HIGH 8.8 CVE-2025-12181 The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function… Mitigation only Fix from $1,9502025-12-05 HIGH 8.8 CVE-2025-12153 The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions … Mitigation only Fix from $1,9502025-12-05 HIGH 8.8 CVE-2025-12154 The Auto Thumbnailer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadThumb() function i… Mitigation only Fix from $1,9502025-12-05 HIGH 8.8 CVE-2025-13066 The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insuff… Mitigation only Fix from $1,9502025-12-05 HIGH 8.8 CVE-2025-13543 The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class… Mitigation only Fix from $1,9502025-12-04 HIGH 7.6 CVE-2025-65027 RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple… Romm 4.4.1+ Fix from $1,9502025-12-03 MEDIUM 6.3 CVE-2025-13949 A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.… Mitigation only Fix from $1,6002025-12-03