Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.4
CVE-2014-125119
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the C…
Mitigation only
HIGH 8.6
CVE-2016-15046
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restri…
Mitigation only
HIGH 8.8
CVE-2013-10032
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated…
Getsimplecms
No fix yet
HIGH 8.8
CVE-2025-5831
The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function…
Droip
after 2.2.0
MEDIUM 6.3
CVE-2025-8128
A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects …
Mitigation only
HIGH 8.8
CVE-2015-10144
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the ima…
Thumbnail Carousel Slider
after 1.0.1
CRITICAL 10.0
CVE-2025-5243
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi…
Mitigation only
CRITICAL 9.8
CVE-2025-7852
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h…
Mitigation only
CRITICAL 9.8
CVE-2025-7437
The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form functio…
Mitigation only
HIGH 7.5
CVE-2025-47187
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit throug…
Mitigation only
CRITICAL 9.1
CVE-2025-40599EPSS 10%
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative pri…
Sma 210 Firmware
10.2.2.1-90sv+
HIGH 7.2
CVE-2025-46099
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the mo…
Pluck
Mitigation only
CRITICAL 9.3
CVE-2018-25114
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing auth…
No fix yet
CRITICAL 9.8
CVE-2025-54448
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
CRITICAL 9.8
CVE-2025-54449
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
HIGH 8.8
CVE-2025-54441EPSS 8%
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
CRITICAL 9.8
CVE-2025-54442
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
CRITICAL 9.8
CVE-2025-54444
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
CRITICAL 9.8
CVE-2025-54447
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
HIGH 8.8
CVE-2025-54439EPSS 7%
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
CRITICAL 9.8
CVE-2025-54440
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…
Magicinfo 9 Server
21.1080.0+
CRITICAL 9.8
CVE-2012-10020
The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions …
Foxypress
after 0.4.2.1
CRITICAL 9.8
CVE-2015-10137
The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up…
Website Contact Form With File Upload
after 1.3.4
HIGH 8.8
CVE-2025-7939
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of t…
Jpacookieshop
No fix yet
CRITICAL 9.4
CVE-2025-54071
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta…
Patch available
HIGH 7.3
CVE-2025-7931
A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown function…
Church Donation System
No fix yet
HIGH 8.1
CVE-2025-54082
marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshm…
Patch available
MEDIUM 6.6
CVE-2025-32744
Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote a…
Appsync
4.6.0.4+
CRITICAL 9.8
CVE-2025-44658
In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensio…
Rax30 Firmware
Mitigation only
HIGH 7.2
CVE-2025-7917
WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privi…
Mitigation only