Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-9415 A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The man… Greencms after 2.3.0603 Fix from $2,3002025-08-25 HIGH 7.5 CVE-2025-53119EPSS 12% An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server. Mitigation only Fix from $1,9502025-08-25 CRITICAL 9.8 CVE-2025-9406 A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the c… Lemon after 1.13.0 Fix from $2,3002025-08-25 HIGH 8.8 CVE-2025-9400 A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This ma… Yifang after 2.0.5 Fix from $1,9502025-08-25 CRITICAL 9.8 CVE-2025-9397 A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipul… Vvveb after 1.0.7.2 Fix from $2,3002025-08-24 HIGH 8.0 CVE-2025-36174 IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be execut… Integrated Analytics System after 1.0.31.0 Fix from $1,9502025-08-24 CRITICAL 9.8 CVE-2025-43766 The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through … Digital Experience Platform 7.4.3.132 / 2024.Q1.14+ Fix from $2,3002025-08-23 HIGH 7.3 CVE-2025-26497 Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Pa… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-08-22 HIGH 7.3 CVE-2025-26498 Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) a… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-08-22 HIGH 8.8 CVE-2025-55454 An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code vi… Dootask No fix yet Fix from $1,9502025-08-22 HIGH 7.1 CVE-2025-54460 The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File … Mitigation only Fix from $1,9502025-08-21 MEDIUM 6.3 CVE-2025-27714 An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code executio… No fix yet Fix from $1,6002025-08-21 MEDIUM 6.3 CVE-2025-24489 An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to system compromise. No fix yet Fix from $1,6002025-08-21 HIGH 8.8 CVE-2025-55743 UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creat… Unopim 0.2.1+ Fix from $1,9502025-08-21 HIGH 8.6 CVE-2025-55383 Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any locat… Mitigation only Fix from $1,9502025-08-21 CRITICAL 9.9 CVE-2025-53251 Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a Web Server.This issue affects… Mitigation only Fix from $2,3002025-08-21 CRITICAL 9.8 CVE-2025-9296 A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_a… Emlog after 2.5.18 Fix from $2,3002025-08-21 MEDIUM 6.8 CVE-2025-49222 Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remo… Mattermost Server 9.11.18 / 10.5.9+ Fix from $1,6002025-08-21 HIGH 7.5 CVE-2025-55746 Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file upd… Directus 11.9.3+ Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-43750 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.… Digital Experience Platform 2024.Q1.15 / 2025.Q1.2+ Fix from $1,6002025-08-20 HIGH 7.2 CVE-2025-54677 Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-… Online Booking \& Scheduling Calendar 4.5.5+ Fix from $1,9502025-08-20 CRITICAL 9.9 CVE-2025-53213 Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping elex-reachsh… Mitigation only Fix from $2,3002025-08-20 CRITICAL 10.0 CVE-2025-48148EPSS 15% Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Usin… Mitigation only Fix from $2,3002025-08-20 HIGH 8.8 CVE-2025-9153 A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin… Online Tour \& Travel Management System No fix yet Fix from $1,9502025-08-19 HIGH 8.2 CVE-2025-8450 Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order… Mitigation only Fix from $1,9502025-08-19 MEDIUM 5.4 CVE-2025-51489 A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when… Moonshine 3.12.5+ Fix from $1,6002025-08-19 MEDIUM 6.3 CVE-2025-9099 A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/… Mitigation only Fix from $1,6002025-08-18 CRITICAL 9.8 CVE-2025-7441EPSS 39% The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs t… Mitigation only Fix from $2,3002025-08-16 HIGH 8.8 CVE-2025-6079 The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ho… Mitigation only Fix from $1,9502025-08-16 CRITICAL 9.2 CVE-2025-54473 An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code executio… Mitigation only Fix from $2,3002025-08-15