Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2025-32028
HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’…
Haxcms Php
10.0.3+
HIGH 8.8
CVE-2025-3410
A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform…
Aias
No fix yet
HIGH 8.8
CVE-2025-2525
The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_Authentication_Controller::ed…
Mitigation only
HIGH 8.8
CVE-2025-3324
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown funct…
Nimrod
No fix yet
CRITICAL 9.8
CVE-2025-32370
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is…
Xperience
13.0.178+
HIGH 8.0
CVE-2025-1500
IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if op…
Maximo Application Suite
9.0.7+
CRITICAL 9.1
CVE-2025-32118
Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using…
Mitigation only
HIGH 8.8
CVE-2025-3244
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vuln…
Web Based Pharmacy Product Management System
No fix yet
HIGH 8.8
CVE-2025-2780
The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the …
Woffice
5.4.22+
HIGH 7.2
CVE-2024-13708
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to …
Booster For Woocommerce
7.2.5+
CRITICAL 9.8
CVE-2024-13744
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_…
Booster For Woocommerce
7.2.5+
MEDIUM 5.0
CVE-2025-3169
A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file …
No fix yet
HIGH 7.2
CVE-2025-3123
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleActio…
Wondercms
No fix yet
CRITICAL 9.8
CVE-2025-2005EPSS 20%
The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the…
Front End Users
after 3.2.32
HIGH 7.2
CVE-2025-27692
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged a…
Wyse Management Suite
5.1+
HIGH 8.8
CVE-2025-2891
The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-…
Mitigation only
HIGH 8.8
CVE-2025-2008
The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …
Mitigation only
CRITICAL 9.8
CVE-2025-3042
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the fi…
Online Time Table Generator
No fix yet
CRITICAL 9.8
CVE-2025-3041
A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /ad…
Online Time Table Generator
No fix yet
CRITICAL 9.8
CVE-2025-3040
A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown fu…
Online Time Table Generator
No fix yet
MEDIUM 6.6
CVE-2025-31577
Unrestricted Upload of File with Dangerous Type vulnerability in appointify Appointify appointify allows Upload a Web Shell to a Web Server.This issu…
Mitigation only
CRITICAL 9.8
CVE-2025-2978
A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?arti…
Wcms
No fix yet
CRITICAL 9.8
CVE-2025-2973
A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file…
College Management System
No fix yet
CRITICAL 9.8
CVE-2025-2952
A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /…
Micro Mall
No fix yet
HIGH 8.8
CVE-2025-2006
The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file…
Mitigation only
HIGH 8.8
CVE-2025-2249
The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the soj_soundslides_options_s…
Mitigation only
CRITICAL 9.8
CVE-2024-56975
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method o…
Invoiceplane
1.6.2+
MEDIUM 6.6
CVE-2025-2819
There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection pro…
Mitigation only
MEDIUM 6.1
CVE-2025-2748EPSS 59%
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for store…
Xperience
after 13.0.178
HIGH 7.2
CVE-2025-2749 KEV
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative …
Xperience
after 13.0.178