Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
MEDIUM 6.3 CVE-2026-10172 A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file ap… Mitigation only Fix from $1,6002026-05-31 HIGH 8.8 CVE-2018-25409 SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code th… No fix yet Fix from $1,9502026-05-30 HIGH 8.8 CVE-2018-25388 HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type val… No fix yet Fix from $1,9502026-05-29 HIGH 7.3 CVE-2026-39292 Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote at… Mitigation only Fix from $1,9502026-05-29 HIGH 7.2 CVE-2026-10072 DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba… Mitigation only Fix from $1,9502026-05-29 CRITICAL 9.8 CVE-2026-10071 DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web she… Mitigation only Fix from $2,3002026-05-29 HIGH 7.3 CVE-2026-30761 An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute … Mitigation only Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9227 The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gute… Patch available Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-9009 The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.… Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.3 CVE-2026-42879 FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability e… Mitigation only Fix from $1,6002026-05-27 HIGH 7.6 CVE-2026-46426 Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process does not enforce active-content… Mitigation only Fix from $1,9502026-05-27 HIGH 8.2 CVE-2026-45089 Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the outp… Mitigation only Fix from $1,9502026-05-27 CRITICAL 9.9 CVE-2026-42748 Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue… Mitigation only Fix from $2,3002026-05-27 MEDIUM 6.3 CVE-2026-9445 A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the… Mitigation only Fix from $1,6002026-05-25 HIGH 7.3 CVE-2026-9421 A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the compo… Mitigation only Fix from $1,9502026-05-25 MEDIUM 6.3 CVE-2026-9374 A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the c… Mitigation only Fix from $1,6002026-05-24 CRITICAL 9.8 CVE-2026-40412 Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. Azure Orbital Spatio Mitigation only Fix from $2,3002026-05-22 MEDIUM 6.9 CVE-2026-9053 Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file p… Mitigation only Fix from $1,6002026-05-22 CRITICAL 9.8 CVE-2026-6960 The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_s… Mitigation only Fix from $2,3002026-05-21 HIGH 7.2 CVE-2026-8134 Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page ty… Concrete Cms after 9.5.0 Fix from $1,9502026-05-21 HIGH 8.4 CVE-2026-9157 Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion. This issu… Mitigation only Fix from $1,9502026-05-21 CRITICAL 9.4 CVE-2026-9102 A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file uploa… Mitigation only Fix from $2,3002026-05-20 CRITICAL 10.0 CVE-2026-45444 Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue a… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-6555 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an arra… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-4883 The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_buil… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-4885 The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_aja… Mitigation only Fix from $2,3002026-05-19 HIGH 7.2 CVE-2026-27891 FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() fu… Patch available Fix from $1,9502026-05-18 HIGH 7.3 CVE-2026-8758 A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp.… Mitigation only Fix from $1,9502026-05-17 HIGH 8.8 CVE-2020-37227 HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension vali… No fix yet Fix from $1,9502026-05-16 HIGH 8.7 CVE-2026-45315 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload end… Open Webui 0.9.3+ Fix from $1,9502026-05-15