Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-6679 The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and incl… Mitigation only Fix from $2,3002025-08-15 HIGH 8.8 CVE-2025-8965 A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/… Litemall after 1.8.0 Fix from $1,9502025-08-14 CRITICAL 9.0 CVE-2025-54693 Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell to a Web Server.This issue a… Mitigation only Fix from $2,3002025-08-14 CRITICAL 9.9 CVE-2025-24775 Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issu… Mitigation only Fix from $2,3002025-08-14 CRITICAL 9.8 CVE-2012-10054 Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes … Umbraco Cms 4.7.1+ Fix from $2,3002025-08-13 HIGH 8.7 CVE-2012-10056 PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can … No fix yet Fix from $1,9502025-08-13 HIGH 7.2 CVE-2025-8297 Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to… Avalanche 6.4.8.8008+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-8859 A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/… Eblog Site No fix yet Fix from $1,9502025-08-11 CRITICAL 9.3 CVE-2012-10038 Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate… No fix yet Fix from $2,3002025-08-11 MEDIUM 6.1 CVE-2025-8841 A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-b… Microservices Platform after 6.0.0 Fix from $1,6002025-08-11 MEDIUM 6.1 CVE-2025-8798 A vulnerability was found in oitcode samarium up to 0.9.6. It has been classified as critical. Affected is an unknown function of the file /dashboard… Samarium after 0.9.6 Fix from $1,6002025-08-10 CRITICAL 9.8 CVE-2025-8775 A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as critical. Affected by this issue is the function ex… Electronic Signature after 4.34 Fix from $2,3002025-08-09 MEDIUM 5.4 CVE-2025-8764 A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upl… Litemall after 1.8.0 Fix from $1,6002025-08-09 CRITICAL 9.3 CVE-2012-10049 WebPageTest version 2.6 and earlier contains an arbitrary file upload vulnerability in the resultimage.php script. The application fails to validate … No fix yet Fix from $2,3002025-08-08 CRITICAL 9.3 CVE-2012-10050 CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_write.php script. The applicati… No fix yet Fix from $2,3002025-08-08 CRITICAL 9.3 CVE-2012-10052 EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The application fails to validate f… No fix yet Fix from $2,3002025-08-08 HIGH 8.7 CVE-2012-10042 Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default cre… No fix yet Fix from $1,9502025-08-08 CRITICAL 10.0 CVE-2012-10044 MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application fails to perform authenticatio… Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.3 CVE-2012-10045 XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. Th… No fix yet Fix from $2,3002025-08-08 CRITICAL 9.3 CVE-2012-10036 Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to … No fix yet Fix from $2,3002025-08-08 MEDIUM 6.4 CVE-2025-55135 In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than… Patch available Fix from $1,6002025-08-07 HIGH 8.2 CVE-2025-51056 An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths … Vedo Suite No fix yet Fix from $1,9502025-08-06 HIGH 8.1 CVE-2025-50286EPSS 9% A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direc… Grav No fix yet Fix from $1,9502025-08-06 CRITICAL 9.8 CVE-2025-22470 CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous files to be uploaded. An arbitrar… Mitigation only Fix from $2,3002025-08-06 MEDIUM 6.5 CVE-2025-52078 File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via… Mitigation only Fix from $1,6002025-08-05 CRITICAL 9.3 CVE-2014-125113 An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5… No fix yet Fix from $2,3002025-08-05 CRITICAL 10.0 CVE-2013-10066 An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an upload endpoint (users_add.php) t… Mitigation only Fix from $2,3002025-08-05 CRITICAL 9.4 CVE-2013-10067 Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the … No fix yet Fix from $2,3002025-08-05 CRITICAL 9.8 CVE-2012-10030 FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive syste… Freefloat Ftp Server Mitigation only Fix from $2,3002025-08-05 CRITICAL 10.0 CVE-2012-10026 The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint … Mitigation only Fix from $2,3002025-08-05