Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.6 CVE-2025-13646 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' fu… Modula Image Gallery 2.13.3+ Fix from $1,6002025-12-03 HIGH 7.5 CVE-2025-65844 EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint i… Evershop No fix yet Fix from $1,9502025-12-02 HIGH 8.8 CVE-2025-13827 Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media … Mitigation only Fix from $1,9502025-12-02 HIGH 8.1 CVE-2025-13516 The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and includ… Mitigation only Fix from $1,9502025-12-02 CRITICAL 9.8 CVE-2025-13815 A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This man… Mogublog after 5.2 Fix from $2,3002025-12-01 MEDIUM 6.3 CVE-2025-51736 File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0. Unica No fix yet Fix from $1,6002025-11-28 HIGH 8.8 CVE-2025-13536 The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, a… Mitigation only Fix from $1,9502025-11-27 CRITICAL 9.8 CVE-2025-66255 Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 3… Mozart Next 3000 Firmware Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-66256 Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300… Mozart Next 100 Firmware Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-66250 Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30… Mozart Next 100 Firmware Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-13597 The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all v… Mitigation only Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-13595 The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all… Mitigation only Fix from $2,3002025-11-25 HIGH 7.2 CVE-2025-13376 The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including… Mitigation only Fix from $1,9502025-11-25 CRITICAL 9.3 CVE-2023-7330 Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacke… Mitigation only Fix from $2,3002025-11-24 HIGH 8.8 CVE-2025-13573 A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_… Advanced Library Management System No fix yet Fix from $1,9502025-11-24 HIGH 7.2 CVE-2025-13574 A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/add… Online Bidding System No fix yet Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-13544 A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the f… Travel Agency after 2025-07-05 Fix from $2,3002025-11-23 HIGH 7.2 CVE-2025-12973 The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missin… Mitigation only Fix from $1,9502025-11-21 HIGH 8.8 CVE-2025-13156 The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… Mitigation only Fix from $1,9502025-11-21 HIGH 8.8 CVE-2025-12138 The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, a… Mitigation only Fix from $1,9502025-11-21 CRITICAL 9.8 CVE-2025-11456 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… Wsdesk 3.3.2+ Fix from $2,3002025-11-21 HIGH 7.2 CVE-2025-0645 Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage allows A… Mitigation only Fix from $1,9502025-11-20 HIGH 7.2 CVE-2025-13423 A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_prod… Retro Basketball Shoes Online Store No fix yet Fix from $1,9502025-11-20 CRITICAL 9.8 CVE-2025-13411 A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the fil… Retro Basketball Shoes Online Store Mitigation only Fix from $2,3002025-11-19 MEDIUM 6.1 CVE-2025-64759 Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a use… Homarr 1.43.3+ Fix from $1,6002025-11-19 MEDIUM 6.9 CVE-2025-34336 eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/in… Mitigation only Fix from $1,6002025-11-19 CRITICAL 9.8 CVE-2025-34328 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that ex… Fax Server after 2.6.23 Fix from $2,3002025-11-19 CRITICAL 9.8 CVE-2025-34329 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at Audio… Fax Server after 2.6.23 Fix from $2,3002025-11-19 MEDIUM 5.3 CVE-2025-34330 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that ex… Fax Server after 2.6.23 Fix from $1,6002025-11-19 CRITICAL 9.8 CVE-2025-12057 The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally… Mitigation only Fix from $2,3002025-11-19