Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-9415
A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The man…
Greencms
after 2.3.0603
HIGH 7.5
CVE-2025-53119EPSS 12%
An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server.
Mitigation only
CRITICAL 9.8
CVE-2025-9406
A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the c…
Lemon
after 1.13.0
HIGH 8.8
CVE-2025-9400
A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This ma…
Yifang
after 2.0.5
CRITICAL 9.8
CVE-2025-9397
A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipul…
Vvveb
after 1.0.7.2
HIGH 8.0
CVE-2025-36174
IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be execut…
Integrated Analytics System
after 1.0.31.0
CRITICAL 9.8
CVE-2025-43766
The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through …
Digital Experience Platform
7.4.3.132 / 2024.Q1.14+
HIGH 7.3
CVE-2025-26497
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Editor modules) allows Absolute Pa…
Tableau Server
2023.3.19 / 2024.2.12+
HIGH 7.3
CVE-2025-26498
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-connection-no-undo modules) a…
Tableau Server
2023.3.19 / 2024.2.12+
HIGH 8.8
CVE-2025-55454
An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code vi…
Dootask
No fix yet
HIGH 7.1
CVE-2025-54460
The vulnerability, if exploited, could allow an authenticated miscreant
(with privileges to create or access publication targets of type Text
File …
Mitigation only
MEDIUM 6.3
CVE-2025-27714
An attacker could exploit this vulnerability by uploading arbitrary
files via the a specific endpoint, leading to unauthorized remote code
executio…
No fix yet
MEDIUM 6.3
CVE-2025-24489
An attacker could exploit this vulnerability by uploading arbitrary
files via a specific service, which could lead to system compromise.
No fix yet
HIGH 8.8
CVE-2025-55743
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creat…
Unopim
0.2.1+
HIGH 8.6
CVE-2025-55383
Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any locat…
Mitigation only
CRITICAL 9.9
CVE-2025-53251
Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a Web Server.This issue affects…
Mitigation only
CRITICAL 9.8
CVE-2025-9296
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_a…
Emlog
after 2.5.18
MEDIUM 6.8
CVE-2025-49222
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remo…
Mattermost Server
9.11.18 / 10.5.9+
HIGH 7.5
CVE-2025-55746
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file upd…
Directus
11.9.3+
MEDIUM 6.5
CVE-2025-43750
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.…
Digital Experience Platform
2024.Q1.15 / 2025.Q1.2+
HIGH 7.2
CVE-2025-54677
Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-…
Online Booking \& Scheduling Calendar
4.5.5+
CRITICAL 9.9
CVE-2025-53213
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping elex-reachsh…
Mitigation only
CRITICAL 10.0
CVE-2025-48148EPSS 15%
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Usin…
Mitigation only
HIGH 8.8
CVE-2025-9153
A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin…
Online Tour \& Travel Management System
No fix yet
HIGH 8.2
CVE-2025-8450
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order…
Mitigation only
MEDIUM 5.4
CVE-2025-51489
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when…
Moonshine
3.12.5+
MEDIUM 6.3
CVE-2025-9099
A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/…
Mitigation only
CRITICAL 9.8
CVE-2025-7441EPSS 39%
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs t…
Mitigation only
HIGH 8.8
CVE-2025-6079
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ho…
Mitigation only
CRITICAL 9.2
CVE-2025-54473
An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code executio…
Mitigation only