Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-7063 Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of… Pad Cms after 1.2.1 Fix from $2,3002025-09-30 CRITICAL 9.8 CVE-2025-7065 Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files o… Pad Cms after 1.2.1 Fix from $2,3002025-09-30 MEDIUM 6.4 CVE-2025-10000 The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… Mitigation only Fix from $1,6002025-09-30 CRITICAL 9.1 CVE-2025-34222 Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployment… Virtual Appliance Application 20.0.2786 / 22.0.1049+ Fix from $2,3002025-09-29 CRITICAL 9.9 CVE-2025-35032 Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how fi… Enterprise Health Mitigation only Fix from $2,3002025-09-29 HIGH 7.2 CVE-2025-11136 A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the comp… Yifang after 2.0.2 Fix from $1,9502025-09-29 HIGH 7.2 CVE-2025-11103 A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality … Online Tours And Travels No fix yet Fix from $1,9502025-09-28 HIGH 8.8 CVE-2025-11078 A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /ad… Open Source Job Portal No fix yet Fix from $1,9502025-09-27 HIGH 8.6 CVE-2025-10544 Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator us… Mitigation only Fix from $1,9502025-09-26 CRITICAL 10.0 CVE-2025-60219 Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a We… Mitigation only Fix from $2,3002025-09-26 HIGH 7.2 CVE-2025-1862 An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SO… Enterprise Integrator Mitigation only Fix from $1,9502025-09-26 HIGH 7.2 CVE-2025-10747 The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file … Mitigation only Fix from $1,9502025-09-26 MEDIUM 6.1 CVE-2025-59525 Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allow… Horilla 1.4.0+ Fix from $1,6002025-09-24 MEDIUM 6.1 CVE-2025-59524 Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in t… Horilla 1.4.0+ Fix from $1,6002025-09-24 CRITICAL 10.0 CVE-2025-9846 Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command In… Mitigation only Fix from $2,3002025-09-23 CRITICAL 9.8 CVE-2025-10412 The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to arbitrary file uploads d… Mitigation only Fix from $2,3002025-09-23 CRITICAL 9.8 CVE-2025-10147 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_origin… Mitigation only Fix from $2,3002025-09-23 HIGH 8.6 CVE-2025-10009 Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute a… Patch available Fix from $1,9502025-09-22 MEDIUM 6.3 CVE-2025-10763 A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by this issue is some unknown func… Mitigation only Fix from $1,6002025-09-21 MEDIUM 6.3 CVE-2025-10755 A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component Content-Type Handler. The ma… Mitigation only Fix from $1,6002025-09-20 MEDIUM 6.3 CVE-2025-10741 A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile … Mitigation only Fix from $1,6002025-09-20 CRITICAL 9.8 CVE-2025-34195 Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments)… Virtual Appliance Application 1.0.735 / 20.0.1330+ Fix from $2,3002025-09-19 HIGH 8.8 CVE-2025-10647 The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_downlo… Mitigation only Fix from $1,9502025-09-19 HIGH 7.3 CVE-2025-55912 An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload … Clipbucket after 5.5.0 Fix from $1,9502025-09-18 MEDIUM 6.3 CVE-2025-10669 A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Per… Mitigation only Fix from $1,6002025-09-18 MEDIUM 5.3 CVE-2025-40678 Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability allows an attacker to upload … Mitigation only Fix from $1,6002025-09-18 HIGH 8.8 CVE-2025-10616 A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipul… E Commerce Website No fix yet Fix from $1,9502025-09-17 HIGH 8.8 CVE-2025-10615 A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipula… E Commerce Website No fix yet Fix from $1,9502025-09-17 CRITICAL 9.8 CVE-2025-10600 A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulatio… Online Exam Form Submission Mitigation only Fix from $2,3002025-09-17 HIGH 8.8 CVE-2025-9216 The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbit… Mitigation only Fix from $1,9502025-09-17