Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 5.4 CVE-2025-7906 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi… Ruoyi after 4.8.1 Fix from $1,6002025-07-20 HIGH 7.2 CVE-2025-7898 A vulnerability was found in Codecanyon iDentSoft 2.0. It has been classified as critical. This affects an unknown part of the file /clinica/profile/… Identsoft No fix yet Fix from $1,9502025-07-20 HIGH 8.8 CVE-2025-46384 CWE-434 Unrestricted Upload of File with Dangerous Type No fix yet Fix from $1,9502025-07-20 CRITICAL 9.8 CVE-2025-7895 A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of … Moneyprinterturbo after 1.2.6 Fix from $2,3002025-07-20 HIGH 8.8 CVE-2025-7880 A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality o… Metacrm after 6.4.2 Fix from $1,9502025-07-20 CRITICAL 9.8 CVE-2025-7879 A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown func… Metacrm after 6.4.2 Fix from $2,3002025-07-20 HIGH 8.8 CVE-2025-7878 A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /c… Metacrm after 6.4.2 Fix from $1,9502025-07-20 CRITICAL 9.8 CVE-2025-7877 A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affects some unknown processin… Metacrm after 6.4.2 Fix from $2,3002025-07-20 MEDIUM 5.4 CVE-2025-7864 A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main… Jeesite 5.12.1+ Fix from $1,6002025-07-20 CRITICAL 9.8 CVE-2015-10138 The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upl… Work The Flow File Upload after 2.5.2 Fix from $2,3002025-07-19 CRITICAL 9.8 CVE-2015-10135 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function… Wpshop 2 1.3.9.6+ Fix from $2,3002025-07-19 CRITICAL 9.8 CVE-2016-15043EPSS 10% The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in version… Wp Mobile Detector after 3.5 Fix from $2,3002025-07-19 CRITICAL 9.8 CVE-2012-10019 The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in vers… Front End Editor 2.3+ Fix from $2,3002025-07-19 CRITICAL 9.8 CVE-2025-46001 An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via up… Filemanager after 2.0.0 Fix from $2,3002025-07-18 HIGH 7.5 CVE-2025-7438 The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_act… Mitigation only Fix from $1,9502025-07-18 CRITICAL 9.8 CVE-2025-6222 The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary … Mitigation only Fix from $2,3002025-07-18 HIGH 8.8 CVE-2025-7755 A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of t… Online Ordering System No fix yet Fix from $1,9502025-07-17 CRITICAL 9.3 CVE-2025-34121 An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post… No fix yet Fix from $2,3002025-07-16 HIGH 8.8 CVE-2025-20274 A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload ar… Unified Intelligence Center Mitigation only Fix from $1,9502025-07-16 CRITICAL 9.1 CVE-2025-48300 Unrestricted Upload of File with Dangerous Type vulnerability in Adrian Tobey Groundhogg groundhogg allows Upload a Web Shell to a Web Server.This is… Mitigation only Fix from $2,3002025-07-16 CRITICAL 10.0 CVE-2025-29009 Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-a… Mitigation only Fix from $2,3002025-07-16 CRITICAL 9.8 CVE-2025-34111 An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's defaul… Tikiwiki Cms\/groupware after 15.1 Fix from $2,3002025-07-15 CRITICAL 9.4 CVE-2025-34104 An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnera… Mitigation only Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-7340 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads … Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks 2.2.2+ Fix from $2,3002025-07-15 CRITICAL 9.8 CVE-2025-7627 A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by t… Kkfileviewofficeedit after 2019-03-19 Fix from $2,3002025-07-14 CRITICAL 9.8 CVE-2025-7547 A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function… Online Movie Theater Seat Reservation System Mitigation only Fix from $2,3002025-07-13 CRITICAL 9.8 CVE-2025-7538 A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pa… Sales And Inventory System Mitigation only Fix from $2,3002025-07-13 MEDIUM 6.3 CVE-2025-7487 A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This… Mitigation only Fix from $1,6002025-07-12 HIGH 7.2 CVE-2025-7477 A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown proc… Simple Car Rental System No fix yet Fix from $1,9502025-07-12 CRITICAL 9.8 CVE-2020-36849 The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins… Csv Import \/ Export after 3.0.3 Fix from $2,3002025-07-12