Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-63228 The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_fi… Mozart Next 100 Firmware Mitigation only Fix from $2,3002025-11-18 HIGH 7.2 CVE-2025-63227 The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php en… Mozart Next 100 Firmware No fix yet Fix from $1,9502025-11-18 CRITICAL 9.8 CVE-2025-63994 An arbitrary file upload vulnerability in the /php/UploadHandler.php component of RichFilemanager v2.7.6 allows attackers to execute arbitrary code v… Richfilemanager Mitigation only Fix from $2,3002025-11-18 CRITICAL 9.8 CVE-2025-63695 DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php. Dzzoffice after 2.3.7 Fix from $2,3002025-11-18 HIGH 8.8 CVE-2025-41735 A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in remote code execution. Ewio2 M Firmware 2.2.0+ Fix from $1,9502025-11-18 CRITICAL 9.8 CVE-2025-41347 Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to uplo… Winplus Mitigation only Fix from $2,3002025-11-18 HIGH 8.8 CVE-2025-13069 The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.1.3. This is… Mitigation only Fix from $1,9502025-11-18 HIGH 8.1 CVE-2025-12528 The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic fun… Mitigation only Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-12775 The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 1.1.0 via the `ajax_u… Mitigation only Fix from $1,9502025-11-18 HIGH 8.1 CVE-2025-12974 The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mecha… Mitigation only Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-63748 QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails… Qatraq No fix yet Fix from $1,9502025-11-17 MEDIUM 6.3 CVE-2025-13249 A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTempl… Mitigation only Fix from $1,6002025-11-16 HIGH 8.8 CVE-2025-13238 A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/pro… Flight Booking Software No fix yet Fix from $1,9502025-11-16 HIGH 7.2 CVE-2025-13185 A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. … News365 after 7.0.3 Fix from $1,9502025-11-14 MEDIUM 6.8 CVE-2025-55810 A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allow… S Cw2503c H Firmware Mitigation only Fix from $1,6002025-11-13 HIGH 8.8 CVE-2025-13061 A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Pe… Online Voting System No fix yet Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-12048 An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote c… Mitigation only Fix from $1,9502025-11-12 HIGH 7.3 CVE-2025-59118 Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommen… Ofbiz 24.09.03+ Fix from $1,9502025-11-12 HIGH 8.8 CVE-2025-12846 The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and including, 2.1.19. This is… Mitigation only Fix from $1,9502025-11-11 CRITICAL 9.8 CVE-2025-11170 The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the Cpiwm_Import… Mitigation only Fix from $2,3002025-11-11 HIGH 7.2 CVE-2025-63678 An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers wi… File Manager No fix yet Fix from $1,9502025-11-10 CRITICAL 9.8 CVE-2021-4462 Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitr… Employee Records System Mitigation only Fix from $2,3002025-11-10 HIGH 7.2 CVE-2025-12867 EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell b… Mitigation only Fix from $1,9502025-11-10 HIGH 7.2 CVE-2025-12399 The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… Mitigation only Fix from $1,9502025-11-08 HIGH 7.2 CVE-2025-11967 The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_impor… Mitigation only Fix from $1,9502025-11-08 HIGH 8.8 CVE-2025-12161 The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creat… Mitigation only Fix from $1,9502025-11-08 CRITICAL 9.8 CVE-2025-12862 A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /… Online Notes Sharing Platform Mitigation only Fix from $2,3002025-11-07 CRITICAL 9.8 CVE-2025-34299EPSS 73% Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execu… Monsta Ftp after 2.11 Fix from $2,3002025-11-07 CRITICAL 9.8 CVE-2025-12352 The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function … Mitigation only Fix from $2,3002025-11-07 MEDIUM 6.1 CVE-2025-64176 ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an attacker can upload any file… Thinkdashboard 0.6.8+ Fix from $1,6002025-11-06