CVE & CISA-KEV Catalog

383,007 CVEs1,677 actively exploited (KEV)
Active:
  • CVSS 6.5 v3·EPSS -·No fix yet

    ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to leave arbitrary files in the storage backend accessible via web server URLs.

    Published 2026-08-25

  • CVSS 5.3 v3·EPSS -·No fix yet

    Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound method in src/reachy_mini/daemon/app/routers/media.py without authentication, file-extension checks, content validation, or size validation. The daemon binds to 0.0.0.0 by default and uses permissive CORS allow_origins=["*"], allowing an unauthenticated network attacker to upload arbitrary file types that are written to /tmp/reachy_mini_sounds/<original_filename>. Malicious files can compromise stored-data integrity and can serve as a foothold when combined with other vulnerabilities. This issue is fixed in version 1.8.2.

    Published 2026-08-25

  • CVSS 7.2 v3·EPSS -·No fix yet

    Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.

    Published 2026-08-25

  • CVSS 9.8 v3·EPSS -·No fix yet

    Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository Management: before 2fb4acee.

    Published 2026-08-25

  • CVSS 4.8 v3·EPSS -·No fix yet

    Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Content-Type using only client-supplied headers without server-side inspection. Attackers with admin privileges can upload SVG or HTML files containing JavaScript that executes in the application origin when accessed by any user, enabling session hijacking and data exfiltration.

    Published 2026-08-25

  • CVSS 8.8 v3·EPSS 0.6%·No fix yet

    The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all versions up to, and including, 2.1.8 via the uploadMedia function. This is due to insufficient file type validation in the upload handler, which performs incomplete extension filtering without MIME-type checks or upload capability verification before passing attacker-supplied files to move_uploaded_file(). This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The required nonce is exposed to any logged-in Subscriber via the CMLOC_Editor_Images JavaScript object on the front-end location editor page.

    Published 2026-08-25

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.

    Published 2026-08-25

  • CVSS 9.9 v3·EPSS 0.4%·No fix yet

    Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

    Published 2026-08-24

  • CVSS 4.8 v4·EPSS 0.3%·No fix yet

    Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.

    Published 2026-08-24

  • CVSS 7.3 v3·EPSS 0.5%·No fix yet

    A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.

    Published 2026-08-24

  • CVSS 7.3 v3·EPSS 0.3%·No fix yet

    A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.

    Published 2026-08-24

  • CVSS 6.1 v3·EPSS 0.2%·No fix yet

    NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects similar to cross-site scripting.

    Published 2026-08-24

  • CVSS 9.1 v3·EPSS 0.7%·No fix yet

    xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code Execution (RCE) on the server, leading to a full system compromise. Version 3.0.4 fixes the issue.

    Published 2026-08-21

  • CVSS 6.3 v3·EPSS 0.3%·No fix yet

    A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be used.

    Published 2026-08-21

  • CVSS 9.4 v4·EPSS 0.5%·No fix yet

    An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to Remote Code Execution (RCE) within the context of the web application. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0402 and on have the patch.

    Published 2026-08-20

  • CVSS 4.7 v3·EPSS 0.2%·No fix yet

    A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

    Published 2026-08-20

  • CVSS 8.7 v4·EPSS 0.4%·No fix yet

    ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated attacker who knows a valid course_id can upload a server-executable malicious script. The uploaded file can then be requested over HTTP, resulting in remote code execution as the web server process user. In most cases, course_id=0 can be used, as it commonly represents the global context. Product is no longer actively supported and the vulnerabilities have not been fixed. Only version 2.2.4 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

    Published 2026-08-20

  • CVSS 9.9 v3·EPSS 0.4%·No fix yet

    Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

    Published 2026-08-20

  • CVSS 9.9 v3·EPSS 0.4%·No fix yet

    Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

    Published 2026-08-20

  • CVSS 9.9 v3·EPSS 0.4%·No fix yet

    Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

    Published 2026-08-20

  • CVSS 9.1 v3·EPSS 0.3%·No fix yet

    Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

    Published 2026-08-20

  • CVSS 7.2 v3·EPSS 0.5%·No fix yet

    A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.

    Published 2026-08-20

  • CVSS 7.2 v3·EPSS 0.5%·No fix yet

    The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.

    Published 2026-08-20

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the argument uploadfile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been published and may be used.

    Published 2026-08-20

  • CVSS 8.7 v3·EPSS 0.4%·No fix yet

    Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavailable and the validation fell back to the attacker-controlled fileObj.type supplied through server/routes/attachmentApi.js. On deployments with WITH_API=true and no file binary, an authenticated board member could label HTML containing JavaScript as image/png, bypass the dangerous MIME check, and store active content under the Wekan origin for execution when another user opened it. Version 9.90 adds looksLikeDangerousMarkup() to inspect file bytes and force dangerous-content scanning when MIME detection is unavailable. This issue is fixed in version

    Published 2026-08-19

  • CVSS 9.0 v3·EPSS 0.6%·No fix yet

    Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

    Published 2026-08-19

  • CVSS 10.0 v4·EPSS 0.3%·No fix yet

    Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.

    Published 2026-08-19

  • CVSS 10.0 v4·EPSS 0.3%·No fix yet

    Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

    Published 2026-08-19

  • CVSS 8.9 v4·EPSS 0.3%·No fix yet

    Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

    Published 2026-08-18

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

    Published 2026-08-18

  • CVSS 9.9 v3·EPSS 0.4%·No fix yet

    Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.

    Published 2026-08-18

  • CVSS 9.9 v3·EPSS 0.4%·No fix yet

    Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

    Published 2026-08-18

  • CVSS 9.9 v3·EPSS 0.3%·No fix yet

    Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

    Published 2026-08-18

  • CVSS 9.6 v3·EPSS 0.2%·No fix yet

    Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

    Published 2026-08-18

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document Upload Controller. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.9.2 is capable of addressing this issue. The identifier of the patch is e945d6bfcec29642f514e7d298dfba2cc6cd7cd4. Upgrading the affected component is recommended.

    Published 2026-08-18

  • CVSS 9.8 v3·EPSS 4.6%·No fix yet

    The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

    Published 2026-08-18

  • CVSS 8.8 v3·EPSS 1.9%·Fix available

    WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

    Published 2026-08-17

  • CVSS 9.8 v3·EPSS 0.6%·No fix yet

    File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

    Published 2026-08-17

  • CVSS 9.8 v3·EPSS 0.6%·No fix yet

    File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

    Published 2026-08-17

  • CVSS 7.2 v3·EPSS 0.5%·No fix yet

    In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.

    Published 2026-08-17

  • CVSS 8.8 v3·EPSS 0.7%·No fix yet

    Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

    Published 2026-08-17

  • CVSS 9.8 v3·EPSS 0.6%·No fix yet

    The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart filename before the file is saved, and a post-save extension check that fails to delete the already-written file. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce required to reach the upload handler is publicly exposed via wp_localize_script on any front-end page rendering the job portal shortcode, allowing unauthenticated visitors to obtain a valid nonce and bypass that gating check

    Published 2026-08-16

  • CVSS 8.8 v3·EPSS 0.5%·No fix yet

    The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_form_ajax handler, combined with unsanitized attacker-controlled options fully replacing saved query options and being passed directly to call_user_func_array() guarded only by function_exists(). This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. Exploitation requires only that at least one query row exists in the database, as the query_id is a small enumerable integer with no further access control.

    Published 2026-08-16

  • CVSS 8.7 v4·EPSS 0.3%·No fix yet

    Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforcing a limit on the resulting uncompressed data. An attacker able to submit a crafted DAA file containing highly compressed data could cause Pandora to decompress a relatively small input into a very large amount of data in memory. Because the decompressed chunks are accumulated to construct the internal ISO image, this could result in excessive memory consumption and potentially CPU exhaustion, causing the extraction worker to become unresponsive, terminate, or affect the availability of the Pandora service. The patch introduces bounded decompression u

    Published 2026-08-15

  • CVSS 8.8 v3·EPSS 0.9%·No fix yet

    The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This is due to a filename validation/destination mismatch in fetch_remote_file, where file type validation is performed against the attacker-controlled Content-Disposition filename rather than the URL-path-derived destination filename. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. A GIF+PHP polyglot file passes wp_check_filetype_and_ext validation as image/gif via the Content-Disposition filename, while the actual destination path is written with a .php extension derived from

    Published 2026-08-15

  • CVSS 8.8 v3·EPSS 0.6%·No fix yet

    The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are applied to the uploaded chunk's filename but not to the final assembled filename derived from the resumableFilename parameter. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

    Published 2026-08-15

  • CVSS 4.7 v3·EPSS 0.2%·No fix yet

    A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.

    Published 2026-08-14

  • CVSS 7.2 v3·EPSS 0.5%·Fix available

    Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

    Published 2026-08-14

  • CVSS 7.2 v3·EPSS 0.4%·Fix available

    Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

    Published 2026-08-14

  • CVSS 6.5 v3·EPSS 0.3%·No fix yet

    Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

    Published 2026-08-13

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.