Total
4396 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-56218 | 1 Ascertia | 1 Signinghub | 2026-07-05 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file. | |||||
| CVE-2025-55835 | 1 Sueamcms Project | 1 Sueamcms | 2026-07-05 | N/A | 9.8 CRITICAL |
| File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering. | |||||
| CVE-2025-52239 | 1 Zkea | 1 Zkeacms | 2026-07-05 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file. | |||||
| CVE-2025-46157 | 1 Efrotech | 1 Timetrax | 2026-07-05 | N/A | 9.9 CRITICAL |
| An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form | |||||
| CVE-2024-48734 | 2026-07-05 | N/A | 8.8 HIGH | ||
| Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file upload is allowed for authorized users. | |||||
| CVE-2026-36387 | 2026-07-05 | N/A | 6.5 MEDIUM | ||
| A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE. | |||||
| CVE-2025-63748 | 1 Testmanagement | 1 Qatraq | 2026-07-05 | N/A | 8.8 HIGH |
| QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, which executes the PHP payload on the server. | |||||
| CVE-2025-60735 | 1 Perfree | 1 Perfreeblog | 2026-07-05 | N/A | 7.6 HIGH |
| PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function | |||||
| CVE-2025-60731 | 1 Perfree | 1 Perfreeblog | 2026-07-05 | N/A | 7.6 HIGH |
| PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function | |||||
| CVE-2025-56704 | 1 Lepton-cms | 1 Leptoncms | 2026-07-05 | N/A | 8.8 HIGH |
| LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit this vulnerability by uploading a specially crafted ZIP/PHP file to execute arbitrary code. | |||||
| CVE-2025-56295 | 1 Carmelo | 1 Computer Laboratory System | 2026-07-05 | N/A | 7.3 HIGH |
| code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions. | |||||
| CVE-2024-44599 | 1 Fntsoftware | 1 Fnt Command | 2026-07-05 | N/A | 8.3 HIGH |
| FNT Command 13.4.0 is vulnerable to Directory Traversal. | |||||
| CVE-2024-44598 | 1 Fntsoftware | 1 Fnt Command | 2026-07-05 | N/A | 8.8 HIGH |
| FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. | |||||
| CVE-2025-52078 | 2026-07-05 | N/A | 6.5 MEDIUM | ||
| File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint. | |||||
| CVE-2025-51056 | 1 Vedo Suite Project | 1 Vedo Suite | 2026-07-05 | N/A | 8.2 HIGH |
| An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE). | |||||
| CVE-2025-46099 | 1 Pluck-cms | 1 Pluck | 2026-07-05 | N/A | 7.2 HIGH |
| In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter. | |||||
| CVE-2025-44139 | 1 Emlog | 1 Emlog | 2026-07-05 | N/A | 7.2 HIGH |
| Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip | |||||
| CVE-2025-29287 | 1 Mingsoft | 1 Mcms | 2026-07-05 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2025-25790 | 1 Foxcms | 1 Foxcms | 2026-07-05 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file. | |||||
| CVE-2025-25784 | 1 Jizhicms | 1 Jizhicms | 2026-07-05 | N/A | 9.8 CRITICAL |
| An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file. | |||||
