Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-12301 A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct… Simple Food Ordering System Mitigation only Fix from $2,3002025-10-27 CRITICAL 9.8 CVE-2025-12268 A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/cour… Learnhouse after 2025-09-21 Fix from $2,3002025-10-27 HIGH 8.8 CVE-2025-12223 A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the co… Flight Booking Software after 3.1 Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-12222 A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the f… Flight Booking Software after 3.1 Fix from $1,9502025-10-27 HIGH 7.2 CVE-2025-12201 A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This affects an unknown part… User Management Php Mysql after 2023-03-16 Fix from $1,9502025-10-27 HIGH 7.6 CVE-2025-60731 PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function Perfreeblog Mitigation only Fix from $1,9502025-10-24 HIGH 7.6 CVE-2025-60735 PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function Perfreeblog Mitigation only Fix from $1,9502025-10-24 HIGH 7.2 CVE-2025-11889 The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the im… Mitigation only Fix from $1,9502025-10-24 CRITICAL 9.8 CVE-2025-6440EPSS 31% The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrar… Mitigation only Fix from $2,3002025-10-24 CRITICAL 10.0 CVE-2025-58963 Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a Web Server.This issue affects … Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.1 CVE-2025-52758 Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy zippy allows Using Malicious Files.This issue affects Z… Mitigation only Fix from $2,3002025-10-22 CRITICAL 10.0 CVE-2025-49060 Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue af… Mitigation only Fix from $2,3002025-10-22 CRITICAL 10.0 CVE-2025-48106 Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clano… Mitigation only Fix from $2,3002025-10-22 HIGH 7.2 CVE-2025-60500 QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in th… Smart School No fix yet Fix from $1,9502025-10-21 MEDIUM 6.5 CVE-2025-61181 daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature. Daicuo No fix yet Fix from $1,6002025-10-21 HIGH 8.8 CVE-2025-61417 Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious… Tastyigniter No fix yet Fix from $1,9502025-10-20 CRITICAL 9.3 CVE-2025-31342 An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum… Mitigation only Fix from $2,3002025-10-20 CRITICAL 9.8 CVE-2025-11948 Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to up… Mitigation only Fix from $2,3002025-10-20 CRITICAL 9.8 CVE-2025-11391 The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… Mitigation only Fix from $2,3002025-10-18 CRITICAL 9.8 CVE-2025-56218 An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file. Signinghub after 8.6.8 Fix from $2,3002025-10-17 HIGH 8.8 CVE-2025-11908 A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the fil… Streamax Crocus No fix yet Fix from $1,9502025-10-17 CRITICAL 9.8 CVE-2023-28814 Some versions of Hikvision's iSecure Center Product have an improper file upload control vulnerability. Due to the improper verification of file to b… Mitigation only Fix from $2,3002025-10-17 HIGH 7.2 CVE-2025-10754 The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functio… Mitigation only Fix from $1,9502025-10-15 CRITICAL 9.8 CVE-2025-10041 The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db(… Mitigation only Fix from $2,3002025-10-15 HIGH 7.2 CVE-2025-10051 The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and inclu… Mitigation only Fix from $1,9502025-10-15 CRITICAL 9.2 CVE-2023-7305 SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or … Mitigation only Fix from $2,3002025-10-15 HIGH 8.6 CVE-2025-61678EPSS 50% FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions pr… Mitigation only Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-37132 An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor oper… Arubaos 8.10.0.19 / 8.12.0.6+ Fix from $1,9502025-10-14 CRITICAL 9.0 CVE-2025-42910 Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files.… Mitigation only Fix from $2,3002025-10-14 HIGH 7.2 CVE-2025-11675 Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute w… Mitigation only Fix from $1,9502025-10-13