Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.3 CVE-2025-2706 A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/Ti… Mitigation only Fix from $1,6002025-03-24 HIGH 7.3 CVE-2025-2705 A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadAp… Mitigation only Fix from $1,9502025-03-24 MEDIUM 6.3 CVE-2025-2702 A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd… Mitigation only Fix from $1,6002025-03-24 CRITICAL 9.8 CVE-2025-2687 A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php… Elearning System No fix yet Fix from $2,3002025-03-24 MEDIUM 6.3 CVE-2025-2671 A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64im… Mitigation only Fix from $1,6002025-03-23 MEDIUM 6.3 CVE-2025-2606 A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is … Best Church Management Software No fix yet Fix from $1,6002025-03-21 MEDIUM 6.3 CVE-2025-2607 A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected by this issue is some unknown … Lzcms Laozhangbokexitong after 1.1.4 Fix from $1,6002025-03-21 CRITICAL 9.8 CVE-2025-29411 An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary … Ibanking No fix yet Fix from $2,3002025-03-20 HIGH 8.8 CVE-2024-9920 In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangero… Lollms Web Ui No fix yet Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2024-8958 In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation… Composio No fix yet Fix from $2,3002025-03-20 CRITICAL 9.1 CVE-2024-8019 In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occur… Pytorch Lightning Patch available Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2024-10901 In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access contr… Db Gpt No fix yet Fix from $2,3002025-03-20 MEDIUM 6.3 CVE-2025-29405 An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows attackers to execute arbitrary co… Emlog after 2.5.7 Fix from $1,6002025-03-19 CRITICAL 9.8 CVE-2025-2512 The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing file type validation in the … File Away after 3.9.9.0.1 Fix from $2,3002025-03-19 HIGH 8.8 CVE-2025-24801EPSS 20% GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI … Glpi 10.0.18+ Fix from $1,9502025-03-18 CRITICAL 9.8 CVE-2024-57169 A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to b… Soplanning No fix yet Fix from $2,3002025-03-18 CRITICAL 9.8 CVE-2025-2494 Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/… Softdial Contact Center Mitigation only Fix from $2,3002025-03-18 HIGH 8.8 CVE-2024-54525 A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2… Ipados 2.2 / 11.2+ Fix from $1,9502025-03-17 HIGH 8.8 CVE-2025-2396 The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and exec… U Office Force 28.0+ Fix from $1,9502025-03-17 HIGH 7.8 CVE-2025-2350 A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown functionality o… Fx2 Firmware after 2025-03-08 Fix from $1,9502025-03-16 CRITICAL 9.8 CVE-2025-2219 A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /ap… Lovecards after 2.3.2 Fix from $2,3002025-03-12 CRITICAL 9.8 CVE-2025-2216 A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the… Warehouse Refinement Management System No fix yet Fix from $2,3002025-03-12 CRITICAL 9.1 CVE-2025-28915 Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Upload a Web Shell to a Web Serve… Mitigation only Fix from $2,3002025-03-11 HIGH 7.1 CVE-2025-22213 Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other… Mitigation only Fix from $1,9502025-03-11 CRITICAL 9.8 CVE-2025-2115 A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRe… Warehouse Refinement Management System No fix yet Fix from $2,3002025-03-09 CRITICAL 9.8 CVE-2024-13359 The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the… Product Input Fields For Woocommerce 1.12.2+ Fix from $2,3002025-03-08 HIGH 8.8 CVE-2024-13882 The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file… Aiomatic 2.3.9+ Fix from $1,9502025-03-08 HIGH 7.2 CVE-2024-13908 The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' functi… Smtp 1.2.0+ Fix from $1,9502025-03-08 CRITICAL 9.8 CVE-2025-25361 An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi… Publiccms No fix yet Fix from $2,3002025-03-06 CRITICAL 9.8 CVE-2025-2035 A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality… Ecommerce Website Using Php No fix yet Fix from $2,3002025-03-06