Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
HIGH 8.1 CVE-2025-1070 CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could render the device inoperable when a malicious file is downlo… Mitigation only Fix from $1,9502025-02-13 HIGH 8.8 CVE-2025-26350 A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or equal to version 2.11.0 allow… Maxtime after 2.11.0 Fix from $1,9502025-02-12 HIGH 8.8 CVE-2024-10960 The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' funct… Brizy 2.6.5+ Fix from $1,9502025-02-12 CRITICAL 9.8 CVE-2024-13365 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip… Security \& Malware Scan 2.150+ Fix from $2,3002025-02-12 HIGH 8.8 CVE-2024-13714 The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… Mitigation only Fix from $1,9502025-02-12 HIGH 8.8 CVE-2025-26411 An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to … Mitigation only Fix from $1,9502025-02-11 HIGH 8.8 CVE-2025-1166 A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown funct… Food Menu Manager No fix yet Fix from $1,9502025-02-11 HIGH 7.3 CVE-2025-1165 A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUpl… Mitigation only Fix from $1,9502025-02-11 CRITICAL 9.8 CVE-2024-13011 The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_prof… Mitigation only Fix from $2,3002025-02-10 HIGH 7.3 CVE-2024-57407 An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafte… Mitigation only Fix from $1,9502025-02-10 HIGH 7.2 CVE-2024-57408 An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading… Cool Admin Java No fix yet Fix from $1,9502025-02-10 HIGH 8.8 CVE-2024-57668 In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability. Shopping Portal No fix yet Fix from $1,9502025-02-06 HIGH 7.5 CVE-2025-1025EPSS 19% Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypa… Patch available Fix from $1,9502025-02-05 HIGH 8.1 CVE-2025-1028 The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the contact form upload featu… Mitigation only Fix from $1,9502025-02-05 HIGH 7.2 CVE-2024-13723 The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able … Mitigation only Fix from $1,9502025-02-04 HIGH 8.8 CVE-2024-57968 KEVEPSS 32% Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible during w… Veracore 2024.4.2.1+ Fix from $1,9502025-02-03 CRITICAL 9.8 CVE-2024-57450 ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function. Chestnutcms after 1.5.0 Fix from $2,3002025-02-03 HIGH 8.8 CVE-2025-24505 This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a spec… Mitigation only Fix from $1,9502025-01-30 MEDIUM 5.4 CVE-2025-23213 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitra… Recipes 1.5.28+ Fix from $1,6002025-01-28 CRITICAL 9.8 CVE-2024-13448 The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_uploads_save_… Addons 2.34.0+ Fix from $2,3002025-01-28 HIGH 7.2 CVE-2025-0722 A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.p… Image Gallery Management System No fix yet Fix from $1,9502025-01-27 CRITICAL 9.8 CVE-2025-0357 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::ha… Wpbookit 1.6.10+ Fix from $2,3002025-01-25 CRITICAL 9.1 CVE-2025-24650 Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic allows Upload a Web Shell to a Web Server.This issue affect… Tourfic 2.15.4+ Fix from $2,3002025-01-24 HIGH 8.8 CVE-2025-0702 A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unk… Bootplus after 2020-08-24 Fix from $1,9502025-01-24 HIGH 8.0 CVE-2024-40693 IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interfa… Planning Analytics Mitigation only Fix from $1,9502025-01-24 HIGH 8.8 CVE-2024-25034 IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. At… Planning Analytics Mitigation only Fix from $1,9502025-01-24 CRITICAL 9.8 CVE-2024-55926 A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By… Workplace Suite 5.6.701.9+ Fix from $2,3002025-01-23 CRITICAL 9.1 CVE-2025-23942 Unrestricted Upload of File with Dangerous Type vulnerability in ngocuct0912 WP Load Gallery wp-load-gallery allows Upload a Web Shell to a Web Serve… Mitigation only Fix from $2,3002025-01-22 CRITICAL 10.0 CVE-2025-23953 Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web Shell to a Web Server.This iss… Mitigation only Fix from $2,3002025-01-22 CRITICAL 9.9 CVE-2025-23918 Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web She… Mitigation only Fix from $2,3002025-01-22