Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.9 CVE-2025-32028 HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’… Haxcms Php 10.0.3+ Fix from $2,3002025-04-08 HIGH 8.8 CVE-2025-3410 A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform… Aias No fix yet Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-2525 The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_Authentication_Controller::ed… Mitigation only Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-3324 A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown funct… Nimrod No fix yet Fix from $1,9502025-04-06 CRITICAL 9.8 CVE-2025-32370 Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is… Xperience 13.0.178+ Fix from $2,3002025-04-06 HIGH 8.0 CVE-2025-1500 IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if op… Maximo Application Suite 9.0.7+ Fix from $1,9502025-04-05 CRITICAL 9.1 CVE-2025-32118 Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using… Mitigation only Fix from $2,3002025-04-04 HIGH 8.8 CVE-2025-3244 A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vuln… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502025-04-04 HIGH 8.8 CVE-2025-2780 The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the … Woffice 5.4.22+ Fix from $1,9502025-04-04 HIGH 7.2 CVE-2024-13708 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to … Booster For Woocommerce 7.2.5+ Fix from $1,9502025-04-04 CRITICAL 9.8 CVE-2024-13744 The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_… Booster For Woocommerce 7.2.5+ Fix from $2,3002025-04-04 MEDIUM 5.0 CVE-2025-3169 A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file … No fix yet Fix from $1,6002025-04-03 HIGH 7.2 CVE-2025-3123 A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleActio… Wondercms No fix yet Fix from $1,9502025-04-02 CRITICAL 9.8 CVE-2025-2005EPSS 20% The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the… Front End Users after 3.2.32 Fix from $2,3002025-04-02 HIGH 7.2 CVE-2025-27692 Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged a… Wyse Management Suite 5.1+ Fix from $1,9502025-04-02 HIGH 8.8 CVE-2025-2891 The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-… Mitigation only Fix from $1,9502025-04-01 HIGH 8.8 CVE-2025-2008 The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … Mitigation only Fix from $1,9502025-04-01 CRITICAL 9.8 CVE-2025-3042 A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the fi… Online Time Table Generator No fix yet Fix from $2,3002025-04-01 CRITICAL 9.8 CVE-2025-3041 A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /ad… Online Time Table Generator No fix yet Fix from $2,3002025-04-01 CRITICAL 9.8 CVE-2025-3040 A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown fu… Online Time Table Generator No fix yet Fix from $2,3002025-03-31 MEDIUM 6.6 CVE-2025-31577 Unrestricted Upload of File with Dangerous Type vulnerability in appointify Appointify appointify allows Upload a Web Shell to a Web Server.This issu… Mitigation only Fix from $1,6002025-03-31 CRITICAL 9.8 CVE-2025-2978 A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?arti… Wcms No fix yet Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2025-2973 A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file… College Management System No fix yet Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2025-2952 A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /… Micro Mall No fix yet Fix from $2,3002025-03-30 HIGH 8.8 CVE-2025-2006 The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file… Mitigation only Fix from $1,9502025-03-29 HIGH 8.8 CVE-2025-2249 The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_s… Mitigation only Fix from $1,9502025-03-29 CRITICAL 9.8 CVE-2024-56975 InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method o… Invoiceplane 1.6.2+ Fix from $2,3002025-03-28 MEDIUM 6.6 CVE-2025-2819 There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection pro… Mitigation only Fix from $1,6002025-03-26 MEDIUM 6.1 CVE-2025-2748EPSS 59% The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for store… Xperience after 13.0.178 Fix from $1,6002025-03-24 HIGH 7.2 CVE-2025-2749 KEV An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative … Xperience after 13.0.178 Fix from $1,9502025-03-24