Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-58480
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upl…
Mitigation only
HIGH 8.8
CVE-2026-14489
The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ve…
Mitigation only
HIGH 8.8
CVE-2026-14158
The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_v…
Mitigation only
HIGH 8.7
CVE-2026-55633
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an aut…
Patch available
HIGH 7.2
CVE-2026-23698
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-l…
Mitigation only
HIGH 8.8
CVE-2026-23697
Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uplo…
Mitigation only
CRITICAL 9.8
CVE-2026-14345
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all ve…
Mitigation only
CRITICAL 9.8
CVE-2026-9182
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi…
Arcgis Server
after 12.0
CRITICAL 9.8
CVE-2026-24014
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…
Iotdb
2.0.8+
MEDIUM 6.3
CVE-2026-14777
A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functiona…
Mitigation only
MEDIUM 6.3
CVE-2026-14775
A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /pro…
Mitigation only
MEDIUM 6.3
CVE-2026-14776
A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the funct…
Mitigation only
HIGH 7.3
CVE-2026-14736
A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Perform…
Mitigation only
MEDIUM 6.3
CVE-2026-14698
A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown functio…
Mitigation only
CRITICAL 9.8
CVE-2024-14037
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading …
Mitigation only
CRITICAL 9.8
CVE-2022-50973
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate…
Mitigation only
CRITICAL 9.8
CVE-2026-5524
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin…
Mitigation only
CRITICAL 9.9
CVE-2026-27419
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
No fix yet
MEDIUM 6.5
CVE-2026-53909
MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse…
Mycomplianceoffice
Mitigation only
CRITICAL 10.0
CVE-2026-48276EPSS 5%
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…
Coldfusion
Mitigation only
CRITICAL 10.0
CVE-2026-48283
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…
Coldfusion
Mitigation only
HIGH 8.6
CVE-2026-53691
An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/…
Mitigation only
HIGH 7.8
CVE-2025-24815
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could all…
Mantaray Nm
25R2-NM+
CRITICAL 9.8
CVE-2026-56290 KEVEPSS 83%
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl…
Page Builder Ck
3.6.0+
HIGH 8.6
CVE-2026-13165
SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with …
Mitigation only
HIGH 7.3
CVE-2026-13553
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller…
Mitigation only
HIGH 7.3
CVE-2026-13547
A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/…
Mitigation only
HIGH 7.2
CVE-2026-56414
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed,…
Mitigation only
HIGH 8.8
CVE-2026-33560
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to …
Dmp 5000 Firmware
8.117.0.0 / 9.43.0.0+
CRITICAL 9.1
CVE-2026-57658
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
Mitigation only