Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 5.4 CVE-2026-39527 Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions. Mitigation only Fix from $1,6002026-06-15 CRITICAL 9.8 CVE-2026-50873 An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via upload… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2018-25436 WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to… Mitigation only Fix from $2,3002026-06-15 MEDIUM 5.3 CVE-2026-34027 The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/u… Mitigation only Fix from $1,6002026-06-15 CRITICAL 9.3 CVE-2026-5482 Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, … Mitigation only Fix from $2,3002026-06-15 HIGH 8.7 CVE-2026-6211 Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properl… Mitigation only Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-53787EPSS 5% Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticate… Mitigation only Fix from $2,3002026-06-12 HIGH 8.1 CVE-2026-46489 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation.… Patch available Fix from $1,9502026-06-11 CRITICAL 9.9 CVE-2026-11839 Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web S… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-7852 Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects Lim… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.1 CVE-2026-9067 The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and… Mitigation only Fix from $2,3002026-06-10 MEDIUM 5.4 CVE-2026-36722 An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary co… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.1 CVE-2025-40808 A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (Al… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-33582 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF ima… Answer 2.0.1+ Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-34031 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not… Answer 2.0.1+ Fix from $1,6002026-06-09 CRITICAL 9.8 CVE-2024-58348 WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitra… Mitigation only Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2024-58349 WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by … Mitigation only Fix from $2,3002026-06-08 HIGH 7.3 CVE-2026-11474 A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown func… Mitigation only Fix from $1,9502026-06-08 HIGH 7.2 CVE-2026-7537 The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send… Mitigation only Fix from $1,9502026-06-06 HIGH 8.7 CVE-2026-46400 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload function… Mitigation only Fix from $1,9502026-06-05 HIGH 8.8 CVE-2026-11419 A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled … On Prem Enterprise Server 8.1.1+ Fix from $1,9502026-06-05 HIGH 8.8 CVE-2026-5411 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbit… Mitigation only Fix from $1,9502026-06-05 HIGH 8.7 CVE-2026-46392 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload… Mitigation only Fix from $1,9502026-06-05 HIGH 7.3 CVE-2026-11344 A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component… Mitigation only Fix from $1,9502026-06-05 MEDIUM 6.3 CVE-2026-11333 A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dc… Mitigation only Fix from $1,6002026-06-05 MEDIUM 6.3 CVE-2026-42538 IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not pr… Mitigation only Fix from $1,6002026-06-04 MEDIUM 6.3 CVE-2026-10806 A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.ph… Mitigation only Fix from $1,6002026-06-04 MEDIUM 6.3 CVE-2026-10807 A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/chang… Mitigation only Fix from $1,6002026-06-04 MEDIUM 6.4 CVE-2026-40548 SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archiv… Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.3 CVE-2026-10205 A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systpa… Mitigation only Fix from $1,6002026-06-01