Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2024-11617 The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'zetra_languageUpload' and… Mitigation only Fix from $2,3002025-05-09 CRITICAL 9.8 CVE-2023-31585 Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php. Mitigation only Fix from $2,3002025-05-08 HIGH 7.2 CVE-2025-47549 Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Upload a Web Shell to a Web Serve… Ultimate Before After Image Slider \& Gallery after 4.6.10 Fix from $1,9502025-05-07 HIGH 7.2 CVE-2025-47550 Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue af… Instantio after 3.3.16 Fix from $1,9502025-05-07 HIGH 8.2 CVE-2025-0984 Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab… Mitigation only Fix from $1,9502025-05-06 CRITICAL 9.8 CVE-2025-40625 Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malic… Gim Mitigation only Fix from $2,3002025-05-06 MEDIUM 6.3 CVE-2025-4333 A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function… Mitigation only Fix from $1,6002025-05-06 MEDIUM 6.3 CVE-2025-4310 A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/… Content Management System No fix yet Fix from $1,6002025-05-06 MEDIUM 6.3 CVE-2025-4305 A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file ap… Mitigation only Fix from $1,6002025-05-06 CRITICAL 9.8 CVE-2025-4291 A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unr… Ideacms after 1.6 Fix from $2,3002025-05-05 HIGH 8.8 CVE-2025-4279 The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'external_image_re… Mitigation only Fix from $1,9502025-05-05 CRITICAL 9.8 CVE-2025-28168 The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size… Multiple File Upload Mitigation only Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-4259 A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/n… Newbee Mall No fix yet Fix from $2,3002025-05-05 HIGH 8.8 CVE-2025-4258 A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youk… Youkefu after 4.2.0 Fix from $1,9502025-05-05 HIGH 8.8 CVE-2024-13418 Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check on the ajaxUploadFonts() func… April after 7.1 Fix from $1,9502025-05-02 MEDIUM 5.4 CVE-2024-11390 Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML a… Kibana 7.17.24 / 8.12.0+ Fix from $1,6002025-05-01 MEDIUM 5.4 CVE-2022-42449 Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications Domino Leap 1.1.1+ Fix from $1,6002025-04-30 MEDIUM 5.4 CVE-2022-27562 Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications. Domino Leap 1.1.1+ Fix from $1,6002025-04-30 CRITICAL 9.4 CVE-2025-0520 An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to re… Patch available Fix from $2,3002025-04-29 CRITICAL 9.8 CVE-2025-3969 A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processi… News Publishing Site Dashboard No fix yet Fix from $2,3002025-04-27 HIGH 8.8 CVE-2025-3914EPSS 15% The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_medi… Aeropage Sync For Airtable 3.3.0+ Fix from $1,9502025-04-26 CRITICAL 9.9 CVE-2025-46616 Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO befo… Mitigation only Fix from $2,3002025-04-25 CRITICAL 9.8 CVE-2025-31324 KEVEPSS 100% SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially ma… Netweaver Mitigation only Fix from $2,3002025-04-24 CRITICAL 9.9 CVE-2025-46264 Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload a Web Shell to a Web Server.T… Mitigation only Fix from $2,3002025-04-24 CRITICAL 9.8 CVE-2025-43946 TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal). Ddi after 11.34p1c2 Fix from $2,3002025-04-22 HIGH 8.8 CVE-2025-3616 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… Greenshift Animation And Page Builder Blocks 11.4.6+ Fix from $1,9502025-04-22 CRITICAL 9.8 CVE-2025-29287 An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted fil… Mcms No fix yet Fix from $2,3002025-04-21 CRITICAL 9.8 CVE-2025-3830 A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUplo… Kuangsimplebbs No fix yet Fix from $2,3002025-04-20 CRITICAL 9.8 CVE-2025-3807 A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com… My Bbs No fix yet Fix from $2,3002025-04-19 HIGH 7.2 CVE-2025-3798 A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminContr… Wcms No fix yet Fix from $1,9502025-04-19