Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.5 CVE-2026-53599 REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/media… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-21662 Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec… Fms Employee after 2025.3.1 Fix from $2,3002026-07-31 HIGH 8.8 CVE-2026-16236 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing … Mitigation only Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-14483 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5… Mitigation only Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-63223 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe c… No fix yet Fix from $2,3002026-07-31 HIGH 8.8 CVE-2026-67206 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-44103 An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware up… No fix yet Fix from $1,6002026-07-30 HIGH 7.1 CVE-2026-44097 A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in … No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-16610 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via… No fix yet Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-65885 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo… Gridbox 2.20.2+ Fix from $1,9502026-07-29 HIGH 8.8 CVE-2026-14270 The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.9 CVE-2026-63227 An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP we… No fix yet Fix from $2,3002026-07-29 HIGH 7.2 CVE-2026-12476 The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insuffic… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-13714 The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload fun… No fix yet Fix from $2,3002026-07-27 HIGH 8.1 CVE-2026-10818 The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_… No fix yet Fix from $1,9502026-07-25 CRITICAL 9.3 CVE-2026-24727 An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System … No fix yet Fix from $2,3002026-07-24 CRITICAL 9.1 CVE-2026-65461 Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. Mitigation only Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-65455 Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-27064 Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-14282 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to ar… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.4 CVE-2026-63048 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authen… No fix yet Fix from $2,3002026-07-22 MEDIUM 6.3 CVE-2026-16451 A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the f… No fix yet Fix from $1,6002026-07-21 HIGH 7.3 CVE-2026-16447 A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The man… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16332 A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipul… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16329 A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16330 A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. T… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16331 A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16327 A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a … No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16324 A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna… No fix yet Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-53593 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous … No fix yet Fix from $1,9502026-07-20