Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 10.0 CVE-2025-6327 Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons allows Upload a Web Shell to a … Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.9 CVE-2025-62065 Unrestricted Upload of File with Dangerous Type vulnerability in Rometheme RTMKit rometheme-for-elementor.This issue affects RTMKit: from n/a through… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.9 CVE-2025-62047 Unrestricted Upload of File with Dangerous Type vulnerability in Case-Themes Case Addons case-addons.This issue affects Case Addons: from n/a through… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.9 CVE-2025-62016 Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. Mitigation only Fix from $2,3002025-11-06 CRITICAL 10.0 CVE-2025-60207 Unrestricted Upload of File with Dangerous Type vulnerability in Addify Custom User Registration Fields for WooCommerce user-registration-plugin-for-… Mitigation only Fix from $2,3002025-11-06 CRITICAL 10.0 CVE-2025-60235 Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium) support-ticket-system-for-wo… Mitigation only Fix from $2,3002025-11-06 CRITICAL 9.1 CVE-2025-58996 Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web … Mitigation only Fix from $2,3002025-11-06 CRITICAL 10.0 CVE-2025-53283 Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-c… Mitigation only Fix from $2,3002025-11-06 HIGH 7.2 CVE-2025-10907 An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP ad… Api Control Plane Mitigation only Fix from $1,9502025-11-05 HIGH 7.2 CVE-2025-20375 A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulne… Unified Contact Center Express 12.5+ Fix from $1,9502025-11-05 HIGH 7.2 CVE-2025-20376 A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulne… Unified Contact Center Express 12.5+ Fix from $1,9502025-11-05 CRITICAL 9.8 CVE-2025-20354 A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arb… Unified Contact Center Express 12.5+ Fix from $2,3002025-11-05 CRITICAL 9.9 CVE-2025-63601 Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file … Snipe It 8.3.3+ Fix from $2,3002025-11-05 HIGH 7.2 CVE-2025-3125 An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpo… Api Control Plane Mitigation only Fix from $1,9502025-11-05 CRITICAL 9.8 CVE-2025-12674 The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the create_media() function in … Mitigation only Fix from $2,3002025-11-05 CRITICAL 9.8 CVE-2025-12682 The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in … Mitigation only Fix from $2,3002025-11-04 HIGH 8.8 CVE-2025-11724 The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all versions up to, and including… Mitigation only Fix from $1,9502025-11-04 HIGH 8.3 CVE-2025-48396 Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in… Mitigation only Fix from $1,9502025-11-03 HIGH 7.2 CVE-2025-12593 A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /… Simple Online Hotel Reservation System No fix yet Fix from $1,9502025-11-02 HIGH 8.8 CVE-2025-11755 The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file uploads when imp… Mitigation only Fix from $1,9502025-11-01 HIGH 8.8 CVE-2025-12171 The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ingest_image(… Mitigation only Fix from $1,9502025-11-01 CRITICAL 9.8 CVE-2025-11499 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to… Mitigation only Fix from $2,3002025-11-01 HIGH 8.0 CVE-2025-62618 ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file.… Elog 3.1.5-20251014+ Fix from $1,9502025-10-31 HIGH 8.8 CVE-2020-36863 Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler di… Nagios Xi 5.7.2+ Fix from $1,9502025-10-30 CRITICAL 9.8 CVE-2025-64095EPSS 45% DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML edito… Dotnetnuke 10.1.1+ Fix from $2,3002025-10-28 CRITICAL 9.8 CVE-2025-12378 A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addprod… Simple Food Ordering System Mitigation only Fix from $2,3002025-10-28 HIGH 8.8 CVE-2025-12347 A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files… Maxsite Cms after 109 Fix from $1,9502025-10-28 HIGH 8.8 CVE-2025-12346 A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_pos… Maxsite Cms after 109 Fix from $1,9502025-10-28 MEDIUM 6.3 CVE-2025-12344 A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet … Mitigation only Fix from $1,6002025-10-28 HIGH 7.2 CVE-2025-12331 A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unr… Willow Cms after 1.4.0 Fix from $1,9502025-10-27