Vulnerability index

Browse CVEs

4,179 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2025-0335 A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this issue is some unknown functiona… Online Bike Rental System No fix yet Fix from $2,3002025-01-09 HIGH 8.8 CVE-2024-13212 A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/jav… Houserent Mitigation only Fix from $1,9502025-01-09 HIGH 7.2 CVE-2024-13210 A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the functio… Bookstore No fix yet Fix from $1,9502025-01-09 HIGH 7.2 CVE-2024-13201 A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the fi… Springboot Blog No fix yet Fix from $1,9502025-01-09 CRITICAL 9.8 CVE-2024-13191 A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/… Myblog No fix yet Fix from $2,3002025-01-08 CRITICAL 9.8 CVE-2025-22137 Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated… Patch available Fix from $2,3002025-01-08 HIGH 8.8 CVE-2024-12854 The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the functionality that a… Mitigation only Fix from $1,9502025-01-08 HIGH 8.8 CVE-2024-12853 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functiona… Modula Image Gallery 2.11.11+ Fix from $1,9502025-01-08 CRITICAL 9.9 CVE-2025-22133 WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controll… Wegia 3.2.8+ Fix from $2,3002025-01-07 CRITICAL 9.8 CVE-2022-41573 An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file c… No fix yet Fix from $2,3002025-01-07 CRITICAL 9.8 CVE-2025-21624 ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functional… Clipbucket 5.5.1-239+ Fix from $2,3002025-01-07 HIGH 8.8 CVE-2024-53345 An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uplo… Mitigation only Fix from $1,9502025-01-07 CRITICAL 10.0 CVE-2024-43243 Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows Upload a Web Shell to a Web Se… Mitigation only Fix from $2,3002025-01-07 CRITICAL 9.8 CVE-2024-56828 File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receiv… Chestnutcms after 1.5.0 Fix from $2,3002025-01-06 CRITICAL 9.8 CVE-2024-13145 A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/mai… My Blog No fix yet Fix from $2,3002025-01-06 CRITICAL 9.8 CVE-2024-13144 A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/ja… My Blog No fix yet Fix from $2,3002025-01-06 HIGH 8.8 CVE-2024-13138 A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file … Mysiteforme No fix yet Fix from $1,9502025-01-05 HIGH 8.8 CVE-2024-13134 A vulnerability, which was classified as critical, was found in ZeroWdd studentmanager 1.0. Affected is the function addTeacher/editTeacher of the fi… Studentmanager Mitigation only Fix from $1,9502025-01-05 HIGH 8.8 CVE-2024-13133 A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStude… Studentmanager Mitigation only Fix from $1,9502025-01-05 CRITICAL 9.8 CVE-2025-0213 A vulnerability was found in Campcodes Project Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of th… Project Management System No fix yet Fix from $2,3002025-01-04 HIGH 8.0 CVE-2025-22389 An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application doe… Optimizely Cms 12.32.0+ Fix from $1,9502025-01-04 CRITICAL 9.8 CVE-2024-55078 An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary cod… Mitigation only Fix from $2,3002025-01-03 MEDIUM 6.6 CVE-2024-56264 Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload a Web Shell to a Web Server.T… Mitigation only Fix from $1,6002025-01-02 CRITICAL 9.1 CVE-2024-56249 Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server… Mitigation only Fix from $2,3002025-01-02 CRITICAL 10.0 CVE-2024-56829 Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fileName element of the UploadFi… Mitigation only Fix from $2,3002025-01-02 CRITICAL 10.0 CVE-2024-56064EPSS 30% Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Ser… Mitigation only Fix from $2,3002024-12-31 CRITICAL 9.8 CVE-2024-56046 Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue a… Wordpress Learning Management System 1.9.9.1+ Fix from $2,3002024-12-31 CRITICAL 9.8 CVE-2024-13022 A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/mai… Tarzan Cms No fix yet Fix from $2,3002024-12-29 HIGH 7.6 CVE-2024-56508 LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerability exists in the LinkAce. This… Linkace 1.15.6+ Fix from $1,9502024-12-27 CRITICAL 9.8 CVE-2024-12956 A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing… Portfolio Management System Mca No fix yet Fix from $2,3002024-12-26