Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.8 CVE-2026-44566 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp,… Open Webui 0.1.124+ Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2021-47965 WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers … Mitigation only Fix from $2,3002026-05-15 HIGH 8.6 CVE-2026-44088 SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes u… Mitigation only Fix from $1,9502026-05-15 MEDIUM 5.4 CVE-2026-22707 Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not en… Strapi 5.33.3+ Fix from $1,6002026-05-14 HIGH 7.2 CVE-2026-41937 Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitr… Patch available Fix from $1,9502026-05-14 CRITICAL 9.8 CVE-2026-6271 The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. T… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.1 CVE-2026-45053 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager … Mitigation only Fix from $2,3002026-05-13 HIGH 7.3 CVE-2026-37430 An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitr… Mitigation only Fix from $1,9502026-05-13 HIGH 8.8 CVE-2026-42844 Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upl… Grav No fix yet Fix from $1,9502026-05-12 HIGH 8.0 CVE-2023-27753 An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file. Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.3 CVE-2025-65416 docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php. Mitigation only Fix from $1,6002026-05-11 HIGH 8.8 CVE-2021-47943 TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading m… No fix yet Fix from $1,9502026-05-10 HIGH 8.8 CVE-2021-47937 e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrar… No fix yet Fix from $1,9502026-05-10 MEDIUM 6.3 CVE-2025-67886 Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execu… Mitigation only Fix from $1,6002026-05-08 MEDIUM 6.5 CVE-2026-36387 A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the fi… Mitigation only Fix from $1,6002026-05-07 HIGH 8.8 CVE-2026-6692 The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_fi… Mitigation only Fix from $1,9502026-05-07 HIGH 8.6 CVE-2026-41587 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From ve… Patch available Fix from $1,9502026-05-07 HIGH 8.8 CVE-2026-41938 Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with medi… Patch available Fix from $1,9502026-05-06 HIGH 8.8 CVE-2026-6261 The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() func… Mitigation only Fix from $1,9502026-05-05 HIGH 7.2 CVE-2026-38751 OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upl… Openstamanager after 2.10 Fix from $1,9502026-05-04 HIGH 7.3 CVE-2026-7733 A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/common/service/UploadService.… Mitigation only Fix from $1,9502026-05-04 MEDIUM 6.3 CVE-2026-7732 A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.ph… Mitigation only Fix from $1,6002026-05-04 HIGH 7.3 CVE-2026-7711 A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wra… Mitigation only Fix from $1,9502026-05-04 MEDIUM 6.3 CVE-2026-7696 A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function … Mitigation only Fix from $1,6002026-05-03 HIGH 7.2 CVE-2026-7490 CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba… Ehrd Cpas Mitigation only Fix from $1,9502026-05-02 CRITICAL 9.8 CVE-2026-4882 The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_A… Mitigation only Fix from $2,3002026-05-02 CRITICAL 9.8 CVE-2022-50993 Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpo… Mitigation only Fix from $2,3002026-04-30 HIGH 8.8 CVE-2026-38991 Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filena… Mitigation only Fix from $1,9502026-04-29 MEDIUM 6.3 CVE-2026-7107 A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This… Mitigation only Fix from $1,6002026-04-27 MEDIUM 6.3 CVE-2026-7044 A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulati… Mitigation only Fix from $1,6002026-04-26