Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 7.6 CVE-2025-2031 A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/… Chestnutcms No fix yet Fix from $1,9502025-03-06 MEDIUM 5.4 CVE-2025-27411 REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5… Redaxo 5.18.3+ Fix from $1,6002025-03-05 HIGH 8.8 CVE-2025-27683 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dange… Vasion Print 1.0.735 / 20.0.1330+ Fix from $1,9502025-03-05 CRITICAL 9.8 CVE-2025-26319EPSS 56% FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. Flowise Patch available Fix from $2,3002025-03-04 HIGH 7.1 CVE-2024-47259 Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation a… Axis Os 11.11.126 / 12.2.52+ Fix from $1,9502025-03-04 CRITICAL 9.8 CVE-2025-1890 A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/ma… Shishuocms No fix yet Fix from $2,3002025-03-04 MEDIUM 6.3 CVE-2025-1835 A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /ap… Mitigation only Fix from $1,6002025-03-02 CRITICAL 9.8 CVE-2025-1834 A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipu… Zz after 2024-8 Fix from $2,3002025-03-02 CRITICAL 9.8 CVE-2025-1818 A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file s… Zz after 2024-8 Fix from $2,3002025-03-02 CRITICAL 9.8 CVE-2025-1791 A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vend… Skycaiji Mitigation only Fix from $2,3002025-03-01 CRITICAL 9.8 CVE-2024-8425 The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'mwb_… Woocommerce Ultimate Gift Card after 2.6.0 Fix from $2,3002025-02-28 CRITICAL 9.8 CVE-2025-26325 ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php. Shopxo No fix yet Fix from $2,3002025-02-27 HIGH 8.8 CVE-2024-41339 An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vi… Vigor165 Firmware 3.9.8 / 3.9.8.9+ Fix from $1,9502025-02-27 HIGH 8.4 CVE-2024-41340 An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 pri… Vigor165 Firmware 3.9.8 / 3.9.8.9+ Fix from $1,9502025-02-27 CRITICAL 9.8 CVE-2025-25783 An arbitrary file upload vulnerability in the component admin\plugin.php of Emlog Pro v2.5.3 allows attackers to execute arbitrary code via uploading… Emlog Mitigation only Fix from $2,3002025-02-26 CRITICAL 9.8 CVE-2025-25784 An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via u… Jizhicms No fix yet Fix from $2,3002025-02-26 CRITICAL 9.8 CVE-2025-25790 An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via… Foxcms No fix yet Fix from $2,3002025-02-26 MEDIUM 6.5 CVE-2025-0731 An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in … Mitigation only Fix from $1,6002025-02-26 CRITICAL 9.8 CVE-2025-1128EPSS 29% The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file… Everest Forms 3.0.9.5+ Fix from $2,3002025-02-25 HIGH 7.3 CVE-2025-1646 A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file … Mitigation only Fix from $1,9502025-02-25 CRITICAL 9.8 CVE-2024-56897 Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can al… Yi Car Dashcam Firmware No fix yet Fix from $2,3002025-02-24 CRITICAL 9.8 CVE-2025-1598 A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is … Best Church Management Software No fix yet Fix from $2,3002025-02-24 CRITICAL 9.8 CVE-2025-1593 A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file… Best Employee Management System Mitigation only Fix from $2,3002025-02-23 HIGH 7.2 CVE-2025-1590 A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /a… E Learning System Mitigation only Fix from $1,9502025-02-23 CRITICAL 10.0 CVE-2025-26776 Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Cha… Mitigation only Fix from $2,3002025-02-22 HIGH 7.2 CVE-2024-13869 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… Wpvivid Backup \& Migration 0.9.113+ Fix from $1,9502025-02-22 CRITICAL 9.8 CVE-2025-1555 A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. … Education And Training System Mitigation only Fix from $2,3002025-02-21 CRITICAL 10.0 CVE-2025-22654 Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious Files.This issue affects Simpl… Mitigation only Fix from $2,3002025-02-18 HIGH 8.8 CVE-2025-1388 Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web sh… Orca Hcm 11.0+ Fix from $1,9502025-02-17 CRITICAL 9.8 CVE-2025-1355 A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functi… Library Card System No fix yet Fix from $2,3002025-02-16