Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-11659 A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this vulnerability … School Management System Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.8 CVE-2025-11660 A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue… School Management System Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.8 CVE-2025-11658 A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown f… School Management System Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.8 CVE-2025-11657 A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This impac… School Management System Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.8 CVE-2025-11656 A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknow… School Management System Mitigation only Fix from $2,3002025-10-13 CRITICAL 9.8 CVE-2025-6553 The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_checkout(… Mitigation only Fix from $2,3002025-10-11 HIGH 8.8 CVE-2025-35055 Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writab… Project Center 2023.1+ Fix from $1,9502025-10-09 CRITICAL 9.8 CVE-2025-11508 A security vulnerability has been detected in code-projects Voting System 1.0. This affects an unknown function of the file /admin/voters_add.php. Su… Voting System Mitigation only Fix from $2,3002025-10-08 HIGH 7.2 CVE-2025-11470 A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function… Hotel And Lodge Management System No fix yet Fix from $1,9502025-10-08 HIGH 8.8 CVE-2025-11436 A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulati… Opnform after 1.9.3 Fix from $1,9502025-10-08 HIGH 8.8 CVE-2025-11426 A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionali… Advanced Library Management System No fix yet Fix from $1,9502025-10-08 HIGH 8.8 CVE-2025-11417 A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unknown code of the file /admin/… Advanced Online Voting System No fix yet Fix from $1,9502025-10-08 HIGH 8.8 CVE-2025-11398 A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unknown function of the file /prof… Hotel And Lodge Management System No fix yet Fix from $1,9502025-10-07 CRITICAL 9.8 CVE-2025-11354 A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Exec… Online Hotel Reservation System Mitigation only Fix from $2,3002025-10-07 HIGH 8.8 CVE-2025-11353 A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of the file /admin/addgalleryexec… Online Hotel Reservation System No fix yet Fix from $1,9502025-10-07 HIGH 8.8 CVE-2025-11351 A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/e… Online Hotel Reservation System No fix yet Fix from $1,9502025-10-07 HIGH 8.8 CVE-2025-11352 A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown function of the file /admin/… Online Hotel Reservation System No fix yet Fix from $1,9502025-10-07 CRITICAL 9.8 CVE-2025-11347 A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file a… Crud Operation System after 3.3 Fix from $2,3002025-10-07 MEDIUM 5.1 CVE-2025-61768 KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists i… Patch available Fix from $1,6002025-10-06 HIGH 8.8 CVE-2025-61687EPSS 10% Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI al… Flowise No fix yet Fix from $1,9502025-10-06 MEDIUM 6.3 CVE-2025-11320 A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main… Mitigation only Fix from $1,6002025-10-06 CRITICAL 9.8 CVE-2025-11318 A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability af… Data Leakage Prevention System Mitigation only Fix from $2,3002025-10-06 MEDIUM 5.4 CVE-2025-61681 KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its file upload functionality that … Patch available Fix from $1,6002025-10-03 HIGH 8.8 CVE-2025-9561 The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insufficient file validation within t… Mitigation only Fix from $1,9502025-10-03 HIGH 7.5 CVE-2025-9212 The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_uploa… Mitigation only Fix from $1,9502025-10-03 HIGH 8.6 CVE-2025-59835 LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/… Patch available Fix from $1,9502025-10-02 HIGH 8.8 CVE-2025-11221 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type vulnerability in GTON… Mitigation only Fix from $1,9502025-10-02 HIGH 8.8 CVE-2025-11020 An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of… Mitigation only Fix from $1,9502025-10-02 HIGH 8.8 CVE-2025-56515 File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file conten… Fiora No fix yet Fix from $1,9502025-10-01 CRITICAL 9.8 CVE-2025-8120 Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files o… Pad Cms after 1.2.1 Fix from $2,3002025-09-30