Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.8 CVE-2025-3054 The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() funct… Mitigation only Fix from $1,9502025-06-05 HIGH 7.2 CVE-2025-20130 A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, r… Identity Services Engine 3.1.0+ Fix from $1,9502025-06-04 HIGH 8.2 CVE-2025-29093 File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Ima… Content Management System No fix yet Fix from $1,9502025-06-04 MEDIUM 6.5 CVE-2025-48953 Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a … Umbraco Cms 15.4.2+ Fix from $1,6002025-06-03 MEDIUM 5.4 CVE-2025-45855 An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via … Erupt after 1.12.19 Fix from $1,6002025-06-03 MEDIUM 6.4 CVE-2025-1725 The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr… Mitigation only Fix from $1,6002025-06-03 MEDIUM 6.8 CVE-2024-7074EPSS 12% An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious … Mitigation only Fix from $1,6002025-06-02 HIGH 8.8 CVE-2025-5406 A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an… Blogbook after 2021-11-22 Fix from $1,9502025-06-01 HIGH 7.5 CVE-2025-48889 Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py… Gradio 5.31.0+ Fix from $1,9502025-05-30 CRITICAL 9.8 CVE-2025-48471 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs insufficient check… Freescout 1.8.179+ Fix from $2,3002025-05-29 MEDIUM 5.3 CVE-2025-46078 HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server Huocms No fix yet Fix from $1,6002025-05-29 MEDIUM 5.3 CVE-2025-46080 HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with spec… Huocms No fix yet Fix from $1,6002025-05-29 HIGH 8.6 CVE-2025-45997 Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an … Web Based Pharmacy Product Management System No fix yet Fix from $1,9502025-05-28 HIGH 7.3 CVE-2025-5299 A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unkno… Client Database Management System No fix yet Fix from $1,9502025-05-28 HIGH 8.8 CVE-2025-4800 The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignm… Mitigation only Fix from $1,9502025-05-28 CRITICAL 9.8 CVE-2025-5178 A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the … Queue Ticket Kiosk after 2025-05-17 Fix from $2,3002025-05-26 CRITICAL 9.8 CVE-2025-5171 A vulnerability, which was classified as critical, has been found in llisoft MTA Maita Training System 4.5. This issue affects the function this.file… Mta Maita Training System Mitigation only Fix from $2,3002025-05-26 CRITICAL 9.8 CVE-2025-5162 A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknow… Seccenter Smp 1114p02 after 20250513 Fix from $2,3002025-05-26 HIGH 7.2 CVE-2025-5131 A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the function uploadCategoryImage… Tmall Demo after 2025-05-05 Fix from $1,9502025-05-24 HIGH 7.2 CVE-2025-5130 A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function uploadProductImage of the file … Tmall Demo after 2025-05-05 Fix from $1,9502025-05-24 CRITICAL 9.8 CVE-2025-5058 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s… Emagicone Store Manager For Woocommerce after 1.2.5 Fix from $2,3002025-05-24 CRITICAL 9.8 CVE-2025-4336 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the s… Emagicone Store Manager For Woocommerce after 1.2.5 Fix from $2,3002025-05-24 CRITICAL 9.8 CVE-2025-5108 A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/cont… Shopxo Mitigation only Fix from $2,3002025-05-23 CRITICAL 10.0 CVE-2025-47687 Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Uplo… Mitigation only Fix from $2,3002025-05-23 HIGH 8.8 CVE-2025-47658 Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-custo… Wsdesk 3.3.0+ Fix from $1,9502025-05-23 CRITICAL 9.9 CVE-2025-47663 Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This … Mitigation only Fix from $2,3002025-05-23 CRITICAL 10.0 CVE-2025-47637 Unrestricted Upload of File with Dangerous Type vulnerability in STAGGS STAGGS staggs allows Upload a Web Shell to a Web Server.This issue affects ST… Mitigation only Fix from $2,3002025-05-23 CRITICAL 10.0 CVE-2025-47641 Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integrat… Mitigation only Fix from $2,3002025-05-23 CRITICAL 10.0 CVE-2025-47642 Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell… Mitigation only Fix from $2,3002025-05-23 CRITICAL 9.9 CVE-2025-46490 Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Upload … Mitigation only Fix from $2,3002025-05-23