Vulnerability index

Browse CVEs

4,170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.2 CVE-2025-5961EPSS 53% The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… Migration\, Backup\, Staging 0.9.117+ Fix from $1,9502025-07-03 CRITICAL 9.8 CVE-2025-5746 The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali… Mitigation only Fix from $2,3002025-07-02 CRITICAL 9.8 CVE-2025-6900 A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /a… Library System Mitigation only Fix from $2,3002025-06-30 HIGH 7.2 CVE-2025-6873 A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown proce… Simple Company Website No fix yet Fix from $1,9502025-06-29 HIGH 7.2 CVE-2025-6872 A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /c… Simple Company Website No fix yet Fix from $1,9502025-06-29 HIGH 8.8 CVE-2025-6848 A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of th… Simple Forum No fix yet Fix from $1,9502025-06-29 CRITICAL 9.8 CVE-2025-6843 A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file … Simple Photo Gallery Mitigation only Fix from $2,3002025-06-29 CRITICAL 9.8 CVE-2025-6837 A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of t… Library System Mitigation only Fix from $2,3002025-06-29 CRITICAL 9.1 CVE-2025-53260 Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress file-manager-plugin-for-wordpress… Mitigation only Fix from $2,3002025-06-27 CRITICAL 10.0 CVE-2025-49885 Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-… Mitigation only Fix from $2,3002025-06-27 CRITICAL 9.8 CVE-2014-0468 Vulnerability in fusionforge in the shipped Apache configuration, where the web server may execute scripts that the users would have uploaded in the… Fusionforge 5.3+ Fix from $2,3002025-06-26 CRITICAL 9.8 CVE-2025-30131 An issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commands by uploa… Fx2 Firmware Mitigation only Fix from $2,3002025-06-26 CRITICAL 10.0 CVE-2025-34046 An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/i… Mitigation only Fix from $2,3002025-06-26 HIGH 8.8 CVE-2025-6667 A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of … Car Rental System No fix yet Fix from $1,9502025-06-25 CRITICAL 9.1 CVE-2021-4457 The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server. Zoomsounds 6.05+ Fix from $2,3002025-06-25 HIGH 8.1 CVE-2025-6435 If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.downl… Firefox 140.0+ Fix from $1,9502025-06-24 HIGH 7.5 CVE-2025-6206 The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file… Aiomatic 2.5.1+ Fix from $1,9502025-06-24 CRITICAL 10.0 CVE-2025-34040EPSS 14% An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters a… Mitigation only Fix from $2,3002025-06-24 CRITICAL 9.8 CVE-2025-6466 A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/u… Ruoyi Ai 2.0.1+ Fix from $2,3002025-06-22 HIGH 8.8 CVE-2025-6422 A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown … Online Recruitment Management System No fix yet Fix from $1,9502025-06-21 HIGH 7.2 CVE-2025-4102 The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… Beaver Builder 2.9.1.1+ Fix from $1,9502025-06-20 CRITICAL 9.8 CVE-2025-6266 A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Per… Flir Ax8 Firmware 1.49.16+ Fix from $2,3002025-06-19 HIGH 7.2 CVE-2025-23171 The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit fil… Mitigation only Fix from $1,9502025-06-19 CRITICAL 9.9 CVE-2025-46157 An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form Timetrax Mitigation only Fix from $2,3002025-06-18 HIGH 7.2 CVE-2025-6220 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_opt… Ultimate Addons For Contact Form 7 3.5.13+ Fix from $1,9502025-06-18 HIGH 7.2 CVE-2025-6086 The CSV Me plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'csv_me_options_page' functio… Mitigation only Fix from $1,9502025-06-18 HIGH 8.8 CVE-2025-4413 The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in… Mitigation only Fix from $1,9502025-06-18 HIGH 8.8 CVE-2025-34511EPSS 16% Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an u… Experience Commerce 10.4+ Fix from $1,9502025-06-17 HIGH 7.5 CVE-2025-47866 An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary fil… Apex Central Mitigation only Fix from $1,9502025-06-17 CRITICAL 10.0 CVE-2025-49444 Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor allows Upload a Web Shell to a W… Mitigation only Fix from $2,3002025-06-17