Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-53599
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/media…
No fix yet
CRITICAL 9.8
CVE-2026-21662
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.
This issue affec…
Fms Employee
after 2025.3.1
HIGH 8.8
CVE-2026-16236
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing …
Mitigation only
CRITICAL 9.8
CVE-2026-14483
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5…
Mitigation only
CRITICAL 9.8
CVE-2026-63223
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe c…
No fix yet
HIGH 8.8
CVE-2026-67206
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr…
No fix yet
MEDIUM 5.3
CVE-2026-44103
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware up…
No fix yet
HIGH 7.1
CVE-2026-44097
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in …
No fix yet
CRITICAL 9.8
CVE-2026-16610
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via…
No fix yet
HIGH 8.8
CVE-2026-65885
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo…
Gridbox
2.20.2+
HIGH 8.8
CVE-2026-14270
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in…
No fix yet
CRITICAL 9.9
CVE-2026-63227
An unrestricted SCORM file upload vulnerability
in Koollab LMS allowed
an authenticated module designer to upload a SCORM package containing a PHP
we…
No fix yet
HIGH 7.2
CVE-2026-12476
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insuffic…
No fix yet
CRITICAL 9.8
CVE-2026-13714
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload fun…
No fix yet
HIGH 8.1
CVE-2026-10818
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_…
No fix yet
CRITICAL 9.3
CVE-2026-24727
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System …
No fix yet
CRITICAL 9.1
CVE-2026-65461
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
Mitigation only
CRITICAL 9.1
CVE-2026-65455
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
No fix yet
CRITICAL 9.1
CVE-2026-27064
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
No fix yet
CRITICAL 9.8
CVE-2026-14282
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to ar…
No fix yet
CRITICAL 9.4
CVE-2026-63048
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authen…
No fix yet
MEDIUM 6.3
CVE-2026-16451
A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the f…
No fix yet
HIGH 7.3
CVE-2026-16447
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The man…
No fix yet
HIGH 7.3
CVE-2026-16332
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipul…
No fix yet
HIGH 7.3
CVE-2026-16329
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation…
No fix yet
HIGH 7.3
CVE-2026-16330
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. T…
No fix yet
HIGH 7.3
CVE-2026-16331
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma…
No fix yet
HIGH 7.3
CVE-2026-16327
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a …
No fix yet
HIGH 7.3
CVE-2026-16324
A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna…
No fix yet
HIGH 8.8
CVE-2026-53593
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous …
No fix yet