Total
4398 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-58048 | 2026-06-17 | N/A | 9.9 CRITICAL | ||
| Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive data extraction from the database, credentials being read from configuration files, and arbitrary system commands being run under the web server user context. This vulnerability was patched by commit 87c3db4 and was released under the version 1.2.11 tag without any other code modifications compared to version 1.2.10. If upgrading is not immediately possible, administrators can mitigate this vulnerability with one or more of the following measures: updating nginx config to download attachments instead of executing them or disallowing access to /storage/ fully using a WAF such as Cloudflare. | |||||
| CVE-2025-57795 | 1 Explorance | 1 Blue | 2026-06-17 | N/A | 9.9 CRITICAL |
| Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be leveraged to achieve remote code execution. | |||||
| CVE-2025-57794 | 1 Explorance | 1 Blue | 2026-06-17 | N/A | 9.1 CRITICAL |
| Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remote code execution under default configurations. | |||||
| CVE-2025-57642 | 1 Sohamjuhin | 1 Tourism Management System | 2026-06-17 | N/A | 7.2 HIGH |
| A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality. | |||||
| CVE-2025-57460 | 1 Machsol | 1 Machpanel | 2026-06-17 | N/A | 9.8 CRITICAL |
| File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell. | |||||
| CVE-2025-57176 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only) with file contents transmitted in cleartext. No authentication or path validation is performed. | |||||
| CVE-2025-57148 | 1 Phpgurukul | 1 Online Shopping Portal | 2026-06-17 | N/A | 9.1 CRITICAL |
| phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation. | |||||
| CVE-2025-56515 | 1 Suisuijiang | 1 Fiora | 2026-06-17 | N/A | 8.8 HIGH |
| File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored. When rendered, these SVG files execute arbitrary JavaScript, enabling attackers to steal user sessions, cookies, and perform unauthorized actions in the context of users viewing affected profiles. | |||||
| CVE-2025-56265 | 1 N8n | 1 N8n | 2026-06-17 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file. | |||||
| CVE-2025-56263 | 1 By-night | 1 Sms | 2026-06-17 | N/A | 8.8 HIGH |
| by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload files of any size and type. | |||||
| CVE-2025-55912 | 1 Oxygenz | 1 Clipbucket | 2026-06-17 | N/A | 7.3 HIGH |
| An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler | |||||
| CVE-2025-55810 | 1 Alagaai | 2 S-cw2503c-h, S-cw2503c-h Firmware | 2026-06-17 | N/A | 6.8 MEDIUM |
| A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allows physical attackers to execute commands as root via script file with a specific name on a SD card. | |||||
| CVE-2025-55746 | 1 Monospace | 1 Directus | 2026-06-17 | N/A | 9.3 CRITICAL |
| Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3. | |||||
| CVE-2025-55743 | 1 Webkul | 1 Unopim | 2026-06-17 | N/A | 8.8 HIGH |
| UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1. | |||||
| CVE-2025-55455 | 1 Dootask | 1 Dootask | 2026-06-17 | N/A | 3.5 LOW |
| DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext. | |||||
| CVE-2025-55454 | 1 Dootask | 1 Dootask | 2026-06-17 | N/A | 8.8 HIGH |
| An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
| CVE-2025-55383 | 2026-06-17 | N/A | 8.6 HIGH | ||
| Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any location on the target server. | |||||
| CVE-2025-55267 | 1 Hcltech | 1 Aftermarket Cloud | 2026-06-17 | N/A | 5.7 MEDIUM |
| HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full control over the server. | |||||
| CVE-2025-55251 | 1 Hcltech | 1 Aion | 2026-06-17 | N/A | 3.1 LOW |
| HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise. | |||||
| CVE-2025-55135 | 2026-06-17 | N/A | 6.4 MEDIUM | ||
| In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG. | |||||
