Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-7470 A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the fil… Sales And Inventory System Mitigation only Fix from $2,3002025-07-12 CRITICAL 9.8 CVE-2020-36847EPSS 18% The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function whic… Simple File List 4.2.3+ Fix from $2,3002025-07-12 HIGH 8.8 CVE-2025-6423 The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_submit_uploa… Mitigation only Fix from $1,9502025-07-12 CRITICAL 9.8 CVE-2025-6058EPSS 6% The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h… Wpbookit 1.0.5+ Fix from $2,3002025-07-12 HIGH 8.8 CVE-2025-6057 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function i… Wpbookit 1.0.5+ Fix from $1,9502025-07-12 HIGH 8.8 CVE-2025-7412 A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of… Library System No fix yet Fix from $1,9502025-07-10 HIGH 8.8 CVE-2025-7413 A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/pro… Library System No fix yet Fix from $1,9502025-07-10 HIGH 8.6 CVE-2025-34097 An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An att… No fix yet Fix from $1,9502025-07-10 CRITICAL 9.3 CVE-2025-34100 An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuer… No fix yet Fix from $2,3002025-07-10 CRITICAL 9.8 CVE-2024-39752 IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore … Analytics Content Hub 2.4+ Fix from $2,3002025-07-10 HIGH 8.8 CVE-2025-7210 A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknow… Library Management System No fix yet Fix from $1,9502025-07-09 CRITICAL 10.0 CVE-2025-34077EPSS 10% An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arb… Mitigation only Fix from $2,3002025-07-09 HIGH 8.8 CVE-2025-7190 A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file… Library Management System No fix yet Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-0928 In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c… Juju 2.9.52 / 3.6.8+ Fix from $1,9502025-07-08 CRITICAL 9.8 CVE-2025-7181 A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /te… Staff Audit System Mitigation only Fix from $2,3002025-07-08 HIGH 7.2 CVE-2025-7175 A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admi… E Commerce Site No fix yet Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-7152 A vulnerability classified as critical has been found in Campcodes Advanced Online Voting System 1.0. Affected is an unknown function of the file /ad… Advanced Online Voting System No fix yet Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-7151 A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been rated as critical. This issue affects some unknown processing o… Advanced Online Voting System No fix yet Fix from $1,9502025-07-07 CRITICAL 9.8 CVE-2025-6802 Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e… Qconvergeconsole after 5.5.0.85 Fix from $2,3002025-07-07 HIGH 8.8 CVE-2025-7124 A vulnerability classified as critical has been found in code-projects Online Note Sharing 1.0. Affected is an unknown function of the file /dashboar… Online Note Sharing No fix yet Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-7114 A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulne… Sim after 0.2.1 Fix from $1,9502025-07-07 CRITICAL 9.8 CVE-2025-7100 A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /appl… Boyuncms after 1.4.20 Fix from $2,3002025-07-07 HIGH 8.8 CVE-2025-7075 A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown fun… Blackvue Dr590x Firmware after 2025-06-24 Fix from $1,9502025-07-06 CRITICAL 10.0 CVE-2025-49414 Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Using Malicious Files.This issue affects FW… Mitigation only Fix from $2,3002025-07-04 CRITICAL 10.0 CVE-2025-30933 Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a Web Shell to a Web Server.Th… Mitigation only Fix from $2,3002025-07-04 CRITICAL 9.1 CVE-2025-28951 Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Upload a Web Shell to a Web… Mitigation only Fix from $2,3002025-07-04 HIGH 7.2 CVE-2025-6586 The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall f… Download Plugin 2.2.9+ Fix from $1,9502025-07-04 HIGH 7.2 CVE-2025-5322 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the d… Vikrentcar 1.4.4+ Fix from $1,9502025-07-03 HIGH 8.8 CVE-2025-34086 Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A … Bolt after 3.7.0 Fix from $1,9502025-07-03 CRITICAL 9.1 CVE-2025-23968 Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server… Mitigation only Fix from $2,3002025-07-03