Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2021-4455 The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… No fix yet Fix from $2,3002025-04-19 CRITICAL 9.8 CVE-2025-1093 The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versi… Mitigation only Fix from $2,3002025-04-19 CRITICAL 9.8 CVE-2025-3783 A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability i… Web Based Pharmacy Product Management System No fix yet Fix from $2,3002025-04-18 HIGH 8.8 CVE-2025-3764 A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unkno… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502025-04-17 HIGH 8.8 CVE-2025-3765 A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affe… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502025-04-17 CRITICAL 9.1 CVE-2025-39436 Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This issue affects I Draw: from n/a… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.9 CVE-2025-32682 Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Upload a Web Shell to a … Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.9 CVE-2025-32652 Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicious Files.This issue affects S… Mitigation only Fix from $2,3002025-04-17 CRITICAL 9.8 CVE-2025-32660 Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager js-jobs allows Upload a Web Shell to a Web Server.This issue … Js Job Manager after 2.0.2 Fix from $2,3002025-04-17 CRITICAL 9.9 CVE-2025-27282 Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator theme-file-duplicator allows Using Malicious Files.… Mitigation only Fix from $2,3002025-04-17 MEDIUM 5.3 CVE-2025-31339 An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allo… Mitigation only Fix from $1,6002025-04-17 CRITICAL 9.8 CVE-2024-40071 Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSetting… Online Id Generator System No fix yet Fix from $2,3002025-04-16 CRITICAL 9.1 CVE-2025-39557 Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allo… Mitigation only Fix from $2,3002025-04-16 MEDIUM 6.6 CVE-2025-39538 Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search allows Upload a Web Shell to … Mitigation only Fix from $1,6002025-04-16 CRITICAL 9.4 CVE-2025-1980 The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If the server is misconfigured, … Mitigation only Fix from $2,3002025-04-16 CRITICAL 10.0 CVE-2025-26927 Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to a Web Server.This issue affec… Mitigation only Fix from $2,3002025-04-15 CRITICAL 9.8 CVE-2025-3593 A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Up… My Blog Layui No fix yet Fix from $2,3002025-04-14 HIGH 8.8 CVE-2025-3585 A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component J… Cicadascms No fix yet Fix from $1,9502025-04-14 HIGH 7.3 CVE-2025-3566 A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the function uploadMdPic… Mitigation only Fix from $1,9502025-04-14 HIGH 7.2 CVE-2025-3565 A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /u… Studentmanager No fix yet Fix from $1,9502025-04-14 CRITICAL 9.8 CVE-2025-3558 A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uplo… Uzy Ssm Mall No fix yet Fix from $2,3002025-04-14 CRITICAL 9.9 CVE-2025-32579 Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload a Web Shell to a Web Server.T… Mitigation only Fix from $2,3002025-04-11 HIGH 8.8 CVE-2025-29017 A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_… Internet Banking System No fix yet Fix from $1,9502025-04-10 MEDIUM 6.5 CVE-2025-32215 Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Stored XSS.This issue a… Mitigation only Fix from $1,6002025-04-10 CRITICAL 9.1 CVE-2025-32202 Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress in… Mitigation only Fix from $2,3002025-04-10 CRITICAL 9.1 CVE-2025-32206 Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Se… Mitigation only Fix from $2,3002025-04-10 CRITICAL 9.9 CVE-2025-32140 Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail wp-remote-thumbnail allows Upload a Web Shell t… Mitigation only Fix from $2,3002025-04-10 CRITICAL 9.1 CVE-2025-31002 Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze squeeze allows Using Malicious Files.This issue affects Sq… Mitigation only Fix from $2,3002025-04-09 HIGH 8.1 CVE-2025-29394 An insecure permissions vulnerability in verydows v2.0 allows a remote attacker to execute arbitrary code by uploading a file type. Mitigation only Fix from $1,9502025-04-09 HIGH 7.2 CVE-2025-27082 Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operat… Arubaos 8.10.0.16 / 8.12.0.4+ Fix from $1,9502025-04-08