Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2025-9941 A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulat… Real Estate Management System No fix yet Fix from $1,9502025-09-04 HIGH 7.2 CVE-2025-6085 The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' funct… Make Connector after 1.5.10 Fix from $1,9502025-09-04 HIGH 8.8 CVE-2025-20287 A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attac… Evolved Programmable Network Manager after 8.0.0 Fix from $1,9502025-09-03 CRITICAL 9.1 CVE-2025-57148 phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation. Online Shopping Portal No fix yet Fix from $2,3002025-09-03 CRITICAL 9.8 CVE-2025-9847 A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This ma… Real Estate Management System Mitigation only Fix from $2,3002025-09-03 HIGH 8.8 CVE-2025-9841 A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewPro… Mobile Shop Management System No fix yet Fix from $1,9502025-09-03 MEDIUM 6.1 CVE-2025-52546 E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan fil… E3 Supervisory Controller Firmware 2.31f01+ Fix from $1,6002025-09-02 MEDIUM 6.1 CVE-2025-9800 A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of th… Sim after 0.3.40 Fix from $1,6002025-09-01 MEDIUM 5.4 CVE-2025-9795 A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jef… Tianti after 2.3 Fix from $1,6002025-09-01 CRITICAL 9.8 CVE-2025-9775 A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the … Remote Clinic after 2.0 Fix from $2,3002025-09-01 CRITICAL 9.8 CVE-2025-9772 A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argu… Remote Clinic after 2.0 Fix from $2,3002025-09-01 CRITICAL 9.9 CVE-2025-31100 Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to a Web Server.This issue affe… Mitigation only Fix from $2,3002025-08-31 HIGH 8.7 CVE-2012-10062 A vulnerability in XAMPP, developed by Apache Friends, version 1.7.3's default WebDAV configuration allows remote authenticated attackers to upload a… No fix yet Fix from $1,9502025-08-30 CRITICAL 10.0 CVE-2009-20011 ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure h… Mitigation only Fix from $2,3002025-08-30 CRITICAL 9.8 CVE-2025-54944 An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers … Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 HIGH 8.8 CVE-2025-58159 WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper… Wegia 3.4.11+ Fix from $1,9502025-08-29 CRITICAL 9.8 CVE-2024-13342 The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_ord… Booster For Woocommerce 7.2.5+ Fix from $2,3002025-08-29 CRITICAL 9.9 CVE-2025-58048 Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows … Patch available Fix from $2,3002025-08-28 MEDIUM 5.4 CVE-2025-31979 A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type res… Mitigation only Fix from $1,6002025-08-28 HIGH 8.8 CVE-2024-13986 Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Cor… Nagios Xi 2024+ Fix from $1,9502025-08-28 CRITICAL 10.0 CVE-2025-49387 Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-… Mitigation only Fix from $2,3002025-08-28 CRITICAL 9.8 CVE-2025-54762 SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS c… Mitigation only Fix from $2,3002025-08-28 CRITICAL 9.8 CVE-2025-53970 SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS c… Mitigation only Fix from $2,3002025-08-28 MEDIUM 6.1 CVE-2024-9648 The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the WP_Ulike_Pro_File_Uploa… Mitigation only Fix from $1,6002025-08-28 CRITICAL 10.0 CVE-2025-34163 Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation a… Mitigation only Fix from $2,3002025-08-27 CRITICAL 10.0 CVE-2024-13981 LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerabil… Mitigation only Fix from $2,3002025-08-27 CRITICAL 10.0 CVE-2023-7309 A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated M… Mitigation only Fix from $2,3002025-08-27 CRITICAL 9.8 CVE-2025-52353 An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP … Badaso Mitigation only Fix from $2,3002025-08-26 CRITICAL 9.8 CVE-2025-9475 A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file… Human Resource Information System Mitigation only Fix from $2,3002025-08-26 CRITICAL 9.8 CVE-2025-9476 A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the f… Human Resource Information System Mitigation only Fix from $2,3002025-08-26