Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.4 CVE-2014-125119 A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the C… Mitigation only Fix from $1,9502025-07-25 HIGH 8.6 CVE-2016-15046 A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restri… Mitigation only Fix from $1,9502025-07-25 HIGH 8.8 CVE-2013-10032 An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated… Getsimplecms No fix yet Fix from $1,9502025-07-25 HIGH 8.8 CVE-2025-5831 The Droip plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the make_google_font_offline() function… Droip after 2.2.0 Fix from $1,9502025-07-25 MEDIUM 6.3 CVE-2025-8128 A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects … Mitigation only Fix from $1,6002025-07-25 HIGH 8.8 CVE-2015-10144 The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the ima… Thumbnail Carousel Slider after 1.0.1 Fix from $1,9502025-07-25 CRITICAL 10.0 CVE-2025-5243 Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi… Mitigation only Fix from $2,3002025-07-24 CRITICAL 9.8 CVE-2025-7852 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h… Mitigation only Fix from $2,3002025-07-24 CRITICAL 9.8 CVE-2025-7437 The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form functio… Mitigation only Fix from $2,3002025-07-24 HIGH 7.5 CVE-2025-47187 A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit throug… Mitigation only Fix from $1,9502025-07-23 CRITICAL 9.1 CVE-2025-40599EPSS 10% An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative pri… Sma 210 Firmware 10.2.2.1-90sv+ Fix from $2,3002025-07-23 HIGH 7.2 CVE-2025-46099 In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the mo… Pluck Mitigation only Fix from $1,9502025-07-23 CRITICAL 9.3 CVE-2018-25114 A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing auth… No fix yet Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54448 Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54449 Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 HIGH 8.8 CVE-2025-54441EPSS 8% Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $1,9502025-07-23 CRITICAL 9.8 CVE-2025-54442 Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54444 Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54447 Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 HIGH 8.8 CVE-2025-54439EPSS 7% Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $1,9502025-07-23 CRITICAL 9.8 CVE-2025-54440 Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2012-10020 The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadify.php file in versions … Foxypress after 0.4.2.1 Fix from $2,3002025-07-22 CRITICAL 9.8 CVE-2015-10137 The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'up… Website Contact Form With File Upload after 1.3.4 Fix from $2,3002025-07-22 HIGH 8.8 CVE-2025-7939 A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of t… Jpacookieshop No fix yet Fix from $1,9502025-07-21 CRITICAL 9.4 CVE-2025-54071 RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta… Patch available Fix from $2,3002025-07-21 HIGH 7.3 CVE-2025-7931 A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown function… Church Donation System No fix yet Fix from $1,9502025-07-21 HIGH 8.1 CVE-2025-54082 marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshm… Patch available Fix from $1,9502025-07-21 MEDIUM 6.6 CVE-2025-32744 Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote a… Appsync 4.6.0.4+ Fix from $1,6002025-07-21 CRITICAL 9.8 CVE-2025-44658 In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensio… Rax30 Firmware Mitigation only Fix from $2,3002025-07-21 HIGH 7.2 CVE-2025-7917 WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privi… Mitigation only Fix from $1,9502025-07-21