Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Tag: cwe-434 Clear
ID Title
CVE-2026-82450 Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
CVE-2026-18983 Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
CVE-2026-81931 Unrestricted File Upload in CVE-2026-81931 (CVE-2026-81931)
vulnerability in CVE-2026-81931 (CVE-2026-81931). Risk of unauthorized operations or information disclosure.
CVE-2026-77991 Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
CVE-2026-75331 Unrestricted File Upload in CVE-2026-75331 (CVE-2026-75331)
vulnerability in CVE-2026-75331 (CVE-2026-75331). Risk of unauthorized operations or information disclosure.
CVE-2026-18080 Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
CVE-2026-79670 Unrestricted File Upload in CVE-2026-79670 (CVE-2026-79670)
vulnerability in CVE-2026-79670 (CVE-2026-79670). Risk of unauthorized operations or information disclosure.
CVE-2026-16601 The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
CVE-2026-78337 Unrestricted File Upload in CVE-2026-78337 (CVE-2026-78337)
vulnerability in CVE-2026-78337 (CVE-2026-78337). Risk of unauthorized operations or information disclosure.
CVE-2026-78245 Vulnerability in CVE-2026-78245 (CVE-2026-78245)
vulnerability in CVE-2026-78245 (CVE-2026-78245). Risk of unauthorized operations or information disclosure.
CVE-2026-78202 Vulnerability in CVE-2026-78202 (CVE-2026-78202)
vulnerability in CVE-2026-78202 (CVE-2026-78202). Risk of unauthorized operations or information disclosure.
CVE-2026-49849 Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
CVE-2026-77681 Vulnerability in CVE-2026-77681 (CVE-2026-77681)
vulnerability in CVE-2026-77681 (CVE-2026-77681). Risk of unauthorized operations or information disclosure.
CVE-2026-76995 Vulnerability in CVE-2026-76995 (CVE-2026-76995)
vulnerability in CVE-2026-76995 (CVE-2026-76995). Risk of unauthorized operations or information disclosure.
CVE-2026-14946 Unrestricted File Upload in CVE-2026-14946 (CVE-2026-14946)
vulnerability in CVE-2026-14946 (CVE-2026-14946). Successful exploitation can lead to full system takeover.
CVE-2026-15049 Unrestricted File Upload in wordpress (CVE-2026-15049)
vulnerability in wordpress (CVE-2026-15049). Successful exploitation can lead to full system takeover.
CVE-2026-76800 Vulnerability in CVE-2026-76800 (CVE-2026-76800)
vulnerability in CVE-2026-76800 (CVE-2026-76800). Risk of unauthorized operations or information disclosure.
CVE-2026-68899 Unrestricted File Upload in CVE-2026-68899 (CVE-2026-68899)
vulnerability in CVE-2026-68899 (CVE-2026-68899). Confidential information can be exposed externally.
CVE-2026-18438 Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
CVE-2026-19839 Vulnerability in CVE-2026-19839 (CVE-2026-19839)
vulnerability in CVE-2026-19839 (CVE-2026-19839). Risk of unauthorized operations or information disclosure.
CVE-2026-49827 Vulnerability in CVE-2026-49827 (CVE-2026-49827)
vulnerability in CVE-2026-49827 (CVE-2026-49827). Successful exploitation can lead to full system takeover.
CVE-2026-18391 Unrestricted File Upload in wordpress (CVE-2026-18391)
vulnerability in wordpress (CVE-2026-18391). Successful exploitation can lead to full system takeover.
CVE-2026-15039 Unrestricted File Upload in wordpress (CVE-2026-15039)
vulnerability in wordpress (CVE-2026-15039). Successful exploitation can lead to full system takeover.
CVE-2026-55676 Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
CVE-2026-13457 Unrestricted File Upload in wordpress (CVE-2026-13457)
vulnerability in wordpress (CVE-2026-13457). Confidential information can be exposed externally.
CVE-2026-72557 Unrestricted File Upload in CVE-2026-72557 (CVE-2026-72557)
vulnerability in CVE-2026-72557 (CVE-2026-72557). Successful exploitation can lead to full system takeover.
CVE-2026-24330 Unrestricted File Upload in CVE-2026-24330 (CVE-2026-24330)
vulnerability in CVE-2026-24330 (CVE-2026-24330). Confidential information can be exposed externally.
CVE-2026-72592 Unrestricted File Upload in CVE-2026-72592 (CVE-2026-72592)
vulnerability in CVE-2026-72592 (CVE-2026-72592). Successful exploitation can lead to full system takeover.
CVE-2026-16985 Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
CVE-2026-19210 Vulnerability in CVE-2026-19210 (CVE-2026-19210)
vulnerability in CVE-2026-19210 (CVE-2026-19210). Risk of unauthorized operations or information disclosure.
CVE-2026-70558 Unrestricted File Upload in CVE-2026-70558 (CVE-2026-70558)
vulnerability in CVE-2026-70558 (CVE-2026-70558). Successful exploitation can lead to full system takeover. Exploitable via `POST /download/uploadFromRsByLocal`.
CVE-2026-19065 Vulnerability in CVE-2026-19065 (CVE-2026-19065)
vulnerability in CVE-2026-19065 (CVE-2026-19065). Risk of unauthorized operations or information disclosure.
CVE-2026-71434 Unrestricted File Upload in statamic/cms (CVE-2026-71434)
vulnerability in statamic/cms (CVE-2026-71434). Risk of unauthorized operations or information disclosure. Exploitable via ``assets``. Mitigation: upgrade to `5.74.3` or later.
CVE-2026-18927 Vulnerability in CVE-2026-18927 (CVE-2026-18927)
vulnerability in CVE-2026-18927 (CVE-2026-18927). Risk of unauthorized operations or information disclosure.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-54416 Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
CVE-2026-14553 Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
CVE-2026-65986 Cross-Site Scripting (XSS) in CVE-2026-65986 (CVE-2026-65986)
cross-site scripting in CVE-2026-65986 (CVE-2026-65986). Risk of unauthorized operations or information disclosure.
CVE-2026-18788 Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
CVE-2026-16618 Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
CVE-2026-61524 Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
CVE-2026-39931 Unrestricted File Upload in sqli (CVE-2026-39931)
vulnerability in sqli (CVE-2026-39931). Successful exploitation can lead to full system takeover.
CVE-2026-16250 Unrestricted File Upload in wordpress (CVE-2026-16250)
vulnerability in wordpress (CVE-2026-16250). Successful exploitation can lead to full system takeover.
CVE-2026-12872 Unrestricted File Upload in wordpress (CVE-2026-12872)
vulnerability in wordpress (CVE-2026-12872). Successful exploitation can lead to full system takeover.
CVE-2026-13157 Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
CVE-2026-13158 Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
CVE-2026-53599 Unrestricted File Upload in redaxo/source (CVE-2026-53599)
vulnerability in redaxo/source (CVE-2026-53599). Successful exploitation can lead to full system takeover. Exploitable via ``shell.php.any.jpg``. Mitigation: upgrade to `5.21.1` or later.
CVE-2026-63223 Unrestricted File Upload in codeigniter4/framework (CVE-2026-63223)
vulnerability in codeigniter4/framework (CVE-2026-63223). Successful exploitation can lead to full system takeover. Exploitable via ``is_image``. Mitigation: upgrade to `4.7.4` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →