Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2026-58480 Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upl… Mitigation only Fix from $2,3002026-07-08 HIGH 8.8 CVE-2026-14489 The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ve… Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-14158 The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_v… Mitigation only Fix from $1,9502026-07-08 HIGH 8.7 CVE-2026-55633 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an aut… Patch available Fix from $1,9502026-07-07 HIGH 7.2 CVE-2026-23698 Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-l… Mitigation only Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-23697 Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uplo… Mitigation only Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2026-14345 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all ve… Mitigation only Fix from $2,3002026-07-07 CRITICAL 9.8 CVE-2026-9182 Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi… Arcgis Server after 12.0 Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici… Iotdb 2.0.8+ Fix from $2,3002026-07-06 MEDIUM 6.3 CVE-2026-14777 A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functiona… Mitigation only Fix from $1,6002026-07-06 MEDIUM 6.3 CVE-2026-14775 A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /pro… Mitigation only Fix from $1,6002026-07-05 MEDIUM 6.3 CVE-2026-14776 A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the funct… Mitigation only Fix from $1,6002026-07-05 HIGH 7.3 CVE-2026-14736 A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Perform… Mitigation only Fix from $1,9502026-07-05 MEDIUM 6.3 CVE-2026-14698 A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown functio… Mitigation only Fix from $1,6002026-07-05 CRITICAL 9.8 CVE-2024-14037 Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading … Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2022-50973 Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate… Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-5524 The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin… Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.9 CVE-2026-27419 Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. No fix yet Fix from $2,3002026-07-02 MEDIUM 6.5 CVE-2026-53909 MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 CRITICAL 10.0 CVE-2026-48276EPSS 5% ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48283 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in… Coldfusion Mitigation only Fix from $2,3002026-06-30 HIGH 8.6 CVE-2026-53691 An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/… Mitigation only Fix from $1,9502026-06-30 HIGH 7.8 CVE-2025-24815 Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could all… Mantaray Nm 25R2-NM+ Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-56290 KEVEPSS 83% Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl… Page Builder Ck 3.6.0+ Fix from $2,3002026-06-29 HIGH 8.6 CVE-2026-13165 SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with … Mitigation only Fix from $1,9502026-06-29 HIGH 7.3 CVE-2026-13553 A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller… Mitigation only Fix from $1,9502026-06-29 HIGH 7.3 CVE-2026-13547 A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/… Mitigation only Fix from $1,9502026-06-29 HIGH 7.2 CVE-2026-56414 A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed,… Mitigation only Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-33560 The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to … Dmp 5000 Firmware 8.117.0.0 / 9.43.0.0+ Fix from $1,9502026-06-26 CRITICAL 9.1 CVE-2026-57658 Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. Mitigation only Fix from $2,3002026-06-26