Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-11617
The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'zetra_languageUpload' and…
Mitigation only
CRITICAL 9.8
CVE-2023-31585
Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php.
Mitigation only
HIGH 7.2
CVE-2025-47549
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Upload a Web Shell to a Web Serve…
Ultimate Before After Image Slider \& Gallery
after 4.6.10
HIGH 7.2
CVE-2025-47550
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue af…
Instantio
after 3.3.16
HIGH 8.2
CVE-2025-0984
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab…
Mitigation only
CRITICAL 9.8
CVE-2025-40625
Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic…
Gim
Mitigation only
MEDIUM 6.3
CVE-2025-4333
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function…
Mitigation only
MEDIUM 6.3
CVE-2025-4310
A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/…
Content Management System
No fix yet
MEDIUM 6.3
CVE-2025-4305
A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file ap…
Mitigation only
CRITICAL 9.8
CVE-2025-4291
A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unr…
Ideacms
after 1.6
HIGH 8.8
CVE-2025-4279
The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_re…
Mitigation only
CRITICAL 9.8
CVE-2025-28168
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size…
Multiple File Upload
Mitigation only
CRITICAL 9.8
CVE-2025-4259
A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/n…
Newbee Mall
No fix yet
HIGH 8.8
CVE-2025-4258
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youk…
Youkefu
after 4.2.0
HIGH 8.8
CVE-2024-13418
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() func…
April
after 7.1
MEDIUM 5.4
CVE-2024-11390
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML a…
Kibana
7.17.24 / 8.12.0+
MEDIUM 5.4
CVE-2022-42449
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
Domino Leap
1.1.1+
MEDIUM 5.4
CVE-2022-27562
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
Domino Leap
1.1.1+
CRITICAL 9.4
CVE-2025-0520
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to re…
Patch available
CRITICAL 9.8
CVE-2025-3969
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processi…
News Publishing Site Dashboard
No fix yet
HIGH 8.8
CVE-2025-3914EPSS 15%
The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_medi…
Aeropage Sync For Airtable
3.3.0+
CRITICAL 9.9
CVE-2025-46616
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO befo…
Mitigation only
CRITICAL 9.8
CVE-2025-31324 KEVEPSS 100%
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma…
Netweaver
Mitigation only
CRITICAL 9.9
CVE-2025-46264
Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload a Web Shell to a Web Server.T…
Mitigation only
CRITICAL 9.8
CVE-2025-43946
TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).
Ddi
after 11.34p1c2
HIGH 8.8
CVE-2025-3616
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i…
Greenshift Animation And Page Builder Blocks
11.4.6+
CRITICAL 9.8
CVE-2025-29287
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted fil…
Mcms
No fix yet
CRITICAL 9.8
CVE-2025-3830
A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUplo…
Kuangsimplebbs
No fix yet
CRITICAL 9.8
CVE-2025-3807
A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com…
My Bbs
No fix yet
HIGH 7.2
CVE-2025-3798
A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminContr…
Wcms
No fix yet