Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.3 CVE-2012-10027 WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadi… No fix yet Fix from $2,3002025-08-05 HIGH 8.8 CVE-2025-5061 The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_… Wp Import Export Lite 3.9.30+ Fix from $1,9502025-08-05 HIGH 8.8 CVE-2025-6207 The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_impo… Wp Import Export Lite 3.9.29+ Fix from $1,9502025-08-05 CRITICAL 9.8 CVE-2025-8526 A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file x… Xboot after 3.3.4 Fix from $2,3002025-08-04 CRITICAL 9.8 CVE-2025-52239 An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file. Zkeacms Mitigation only Fix from $2,3002025-08-04 CRITICAL 9.3 CVE-2013-10054 An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contains an unauthenticated arbitra… No fix yet Fix from $2,3002025-08-04 MEDIUM 6.4 CVE-2025-54962 /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these … Mitigation only Fix from $1,6002025-08-04 CRITICAL 9.8 CVE-2025-8504 A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userreg… Kitchen Treasure Mitigation only Fix from $2,3002025-08-03 CRITICAL 9.3 CVE-2013-10055 An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The appl… No fix yet Fix from $2,3002025-08-01 HIGH 8.8 CVE-2013-10044 An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator creden… Openemr after 4.1.1 Fix from $1,9502025-08-01 CRITICAL 9.3 CVE-2013-10047 An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary… No fix yet Fix from $2,3002025-08-01 HIGH 7.2 CVE-2025-44139 Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip Emlog No fix yet Fix from $1,9502025-08-01 HIGH 8.1 CVE-2025-7443 The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulner… Mitigation only Fix from $1,9502025-08-01 CRITICAL 9.2 CVE-2014-125126 An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentic… No fix yet Fix from $2,3002025-07-31 CRITICAL 9.5 CVE-2013-10043 A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the logon.php script allows an at… No fix yet Fix from $2,3002025-07-31 CRITICAL 9.3 CVE-2013-10038 An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to p… No fix yet Fix from $2,3002025-07-31 CRITICAL 9.8 CVE-2013-10040 ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. T… Clipbucket after 2.6 Fix from $2,3002025-07-31 CRITICAL 9.3 CVE-2013-10034 An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated use… No fix yet Fix from $2,3002025-07-31 HIGH 7.2 CVE-2025-8379 A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an unknown part of the file /adm… Online Hotel Reservation System No fix yet Fix from $1,9502025-07-31 HIGH 8.0 CVE-2025-54757 Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a produc… Powercms 4.61 / 5.31+ Fix from $1,9502025-07-31 HIGH 8.8 CVE-2025-7847 The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() functio… Mitigation only Fix from $1,9502025-07-31 CRITICAL 9.8 CVE-2025-8344 A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-ap… Shio after 0.3.8 Fix from $2,3002025-07-31 HIGH 8.8 CVE-2025-8323 The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoo… Mitigation only Fix from $1,9502025-07-30 HIGH 8.8 CVE-2025-54769 An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing… Lpar2rrd after 8.04 Fix from $1,9502025-07-29 CRITICAL 9.8 CVE-2025-8256 A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin… Online Ordering System Mitigation only Fix from $2,3002025-07-28 CRITICAL 9.8 CVE-2025-8255 A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the… Exam Form Submission Mitigation only Fix from $2,3002025-07-28 MEDIUM 6.3 CVE-2025-8174 A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the … Voting System No fix yet Fix from $1,6002025-07-26 MEDIUM 6.3 CVE-2025-8171 A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some unknown pr… Document Management System Mitigation only Fix from $1,6002025-07-25 HIGH 8.5 CVE-2025-52449 Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) al… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-07-25 CRITICAL 9.3 CVE-2014-125116 A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the install.php installation script. T… No fix yet Fix from $2,3002025-07-25