Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.0 CVE-2025-23921 Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell … Mitigation only Fix from $2,3002025-01-22 CRITICAL 9.8 CVE-2024-13091 The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_f… Wpot 13.5.6+ Fix from $2,3002025-01-22 CRITICAL 9.1 CVE-2025-22723 Unrestricted Upload of File with Dangerous Type vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager bar… Mitigation only Fix from $2,3002025-01-21 CRITICAL 9.0 CVE-2024-51919 Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Produ… Mitigation only Fix from $2,3002025-01-21 HIGH 7.2 CVE-2025-0582 A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the fil… Tailoring Management System No fix yet Fix from $1,9502025-01-20 HIGH 7.5 CVE-2024-13333 The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_sys… Advanced File Manager 5.2.14+ Fix from $1,9502025-01-17 HIGH 7.5 CVE-2025-0472 Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environ… Pmb after 4.2.13 Fix from $1,9502025-01-16 CRITICAL 9.8 CVE-2025-0471 Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload… Pmb Mitigation only Fix from $2,3002025-01-16 MEDIUM 5.4 CVE-2024-13355 The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficien… Mitigation only Fix from $1,6002025-01-16 MEDIUM 6.5 CVE-2024-41454 An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execu… Mitigation only Fix from $1,6002025-01-15 CRITICAL 9.9 CVE-2025-22782 Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce al… Mitigation only Fix from $2,3002025-01-15 HIGH 8.1 CVE-2024-57761 An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploadin… Jeewms 2025-01-01+ Fix from $1,9502025-01-15 CRITICAL 9.8 CVE-2024-48760EPSS 45% An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perl… Gestioip No fix yet Fix from $2,3002025-01-14 HIGH 7.8 CVE-2024-13171EPSS 18% Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote… Endpoint Manager 2022+ Fix from $1,9502025-01-14 CRITICAL 9.8 CVE-2025-0463 A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an … Lingdang Crm Mitigation only Fix from $2,3002025-01-14 HIGH 7.3 CVE-2025-0460 A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file… Mitigation only Fix from $1,9502025-01-14 HIGH 8.8 CVE-2025-0394 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file upload… Mitigation only Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2023-42248 An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating P… Visual Access Manager 4.42.2+ Fix from $1,6002025-01-13 HIGH 8.8 CVE-2024-46479 Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a maliciou… Supravizio Bpm after 18.0.1 Fix from $1,9502025-01-13 HIGH 8.8 CVE-2025-0402 A vulnerability classified as critical was found in 1902756969 reggie 1.0. Affected by this vulnerability is the function upload of the file src/main… Reggie Mitigation only Fix from $1,9502025-01-13 HIGH 7.2 CVE-2025-0399 A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController o… Starsea Mall Mitigation only Fix from $1,9502025-01-12 CRITICAL 9.8 CVE-2024-42180 HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, including incorrect content types… Dryice Myxalytics Mitigation only Fix from $2,3002025-01-12 CRITICAL 9.1 CVE-2025-22152 Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple component… Mitigation only Fix from $2,3002025-01-10 HIGH 7.2 CVE-2024-46210 An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a craft… Redaxo Mitigation only Fix from $1,9502025-01-10 CRITICAL 10.0 CVE-2025-22504 Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-webforms allows Upload a Web Shell to a Web Server.… Mitigation only Fix from $2,3002025-01-09 HIGH 7.2 CVE-2025-0346 A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the fil… Content Management System No fix yet Fix from $1,9502025-01-09 CRITICAL 9.8 CVE-2025-0341 A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0. Affected by this issue is s… Computer Laboratory Management System No fix yet Fix from $2,3002025-01-09 MEDIUM 5.3 CVE-2024-43662 The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any user, although the… Mitigation only Fix from $1,6002025-01-09 HIGH 8.8 CVE-2024-43656 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff… Mitigation only Fix from $1,9502025-01-09 HIGH 8.8 CVE-2024-43657 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue aff… Mitigation only Fix from $1,9502025-01-09