Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-434 Clear
ID Title
CVE-2026-11621 Vulnerability in CVE-2026-11621 (CVE-2026-11621)
vulnerability in CVE-2026-11621 (CVE-2026-11621). Risk of unauthorized operations or information disclosure.
CVE-2024-58348 Unrestricted File Upload in wordpress (CVE-2024-58348)
vulnerability in wordpress (CVE-2024-58348). Successful exploitation can lead to full system takeover.
CVE-2024-58349 Unrestricted File Upload in wordpress (CVE-2024-58349)
vulnerability in wordpress (CVE-2024-58349). Successful exploitation can lead to full system takeover.
CVE-2026-11474 Vulnerability in CVE-2026-11474 (CVE-2026-11474)
vulnerability in CVE-2026-11474 (CVE-2026-11474). Risk of unauthorized operations or information disclosure.
CVE-2026-7537 Unrestricted File Upload in wordpress (CVE-2026-7537)
vulnerability in wordpress (CVE-2026-7537). Successful exploitation can lead to full system takeover.
CVE-2026-46400 Unrestricted File Upload in CVE-2026-46400 (CVE-2026-46400)
vulnerability in CVE-2026-46400 (CVE-2026-46400). Risk of unauthorized operations or information disclosure.
CVE-2026-11419 Path Traversal in path-traversal (CVE-2026-11419)
path traversal in path-traversal (CVE-2026-11419). Successful exploitation can lead to full system takeover.
CVE-2026-5411 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-46392 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
CVE-2026-11344 Vulnerability in CVE-2026-11344 (CVE-2026-11344)
vulnerability in CVE-2026-11344 (CVE-2026-11344). Risk of unauthorized operations or information disclosure.
CVE-2026-11333 Vulnerability in CVE-2026-11333 (CVE-2026-11333)
vulnerability in CVE-2026-11333 (CVE-2026-11333). Risk of unauthorized operations or information disclosure.
CVE-2026-42538 Unrestricted File Upload in CVE-2026-42538 (CVE-2026-42538)
vulnerability in CVE-2026-42538 (CVE-2026-42538). Confidential information can be exposed externally.
CVE-2026-10806 Vulnerability in CVE-2026-10806 (CVE-2026-10806)
vulnerability in CVE-2026-10806 (CVE-2026-10806). Risk of unauthorized operations or information disclosure.
CVE-2026-10807 Vulnerability in CVE-2026-10807 (CVE-2026-10807)
vulnerability in CVE-2026-10807 (CVE-2026-10807). Risk of unauthorized operations or information disclosure.
CVE-2026-40548 Unrestricted File Upload in path-traversal (CVE-2026-40548)
vulnerability in path-traversal (CVE-2026-40548). Risk of unauthorized operations or information disclosure.
CVE-2026-10205 Vulnerability in CVE-2026-10205 (CVE-2026-10205)
vulnerability in CVE-2026-10205 (CVE-2026-10205). Risk of unauthorized operations or information disclosure.
CVE-2026-10172 Vulnerability in CVE-2026-10172 (CVE-2026-10172)
vulnerability in CVE-2026-10172 (CVE-2026-10172). Risk of unauthorized operations or information disclosure.
CVE-2018-25409 Unrestricted File Upload in CVE-2018-25409 (CVE-2018-25409)
vulnerability in CVE-2018-25409 (CVE-2018-25409). Successful exploitation can lead to full system takeover.
CVE-2018-25388 Unrestricted File Upload in CVE-2018-25388 (CVE-2018-25388)
vulnerability in CVE-2018-25388 (CVE-2018-25388). Successful exploitation can lead to full system takeover.
CVE-2026-39292 Unrestricted File Upload in CVE-2026-39292 (CVE-2026-39292)
vulnerability in CVE-2026-39292 (CVE-2026-39292). Risk of unauthorized operations or information disclosure.
CVE-2026-10072 Unrestricted File Upload in CVE-2026-10072 (CVE-2026-10072)
vulnerability in CVE-2026-10072 (CVE-2026-10072). Successful exploitation can lead to full system takeover.
CVE-2026-10071 Unrestricted File Upload in CVE-2026-10071 (CVE-2026-10071)
vulnerability in CVE-2026-10071 (CVE-2026-10071). Successful exploitation can lead to full system takeover.
CVE-2026-30761 Unrestricted File Upload in CVE-2026-30761 (CVE-2026-30761)
vulnerability in CVE-2026-30761 (CVE-2026-30761). Risk of unauthorized operations or information disclosure.
CVE-2026-9227 Unrestricted File Upload in wordpress (CVE-2026-9227)
vulnerability in wordpress (CVE-2026-9227). Successful exploitation can lead to full system takeover.
CVE-2026-9009 Unrestricted File Upload in wordpress (CVE-2026-9009)
vulnerability in wordpress (CVE-2026-9009). Successful exploitation can lead to full system takeover.
CVE-2026-42748 Unrestricted File Upload in CVE-2026-42748 (CVE-2026-42748)
vulnerability in CVE-2026-42748 (CVE-2026-42748). Successful exploitation can lead to full system takeover.
CVE-2026-9445 Vulnerability in CVE-2026-9445 (CVE-2026-9445)
vulnerability in CVE-2026-9445 (CVE-2026-9445). Risk of unauthorized operations or information disclosure.
CVE-2026-9421 Vulnerability in CVE-2026-9421 (CVE-2026-9421)
vulnerability in CVE-2026-9421 (CVE-2026-9421). Risk of unauthorized operations or information disclosure.
CVE-2026-9374 Vulnerability in vue (CVE-2026-9374)
vulnerability in vue (CVE-2026-9374). Risk of unauthorized operations or information disclosure.
CVE-2026-40412 Unrestricted File Upload in microsoft (CVE-2026-40412)
vulnerability in microsoft (CVE-2026-40412). Successful exploitation can lead to full system takeover.
CVE-2026-9053 Unrestricted File Upload in CVE-2026-9053 (CVE-2026-9053)
vulnerability in CVE-2026-9053 (CVE-2026-9053). Risk of unauthorized operations or information disclosure.
CVE-2026-6960 Unrestricted File Upload in wordpress (CVE-2026-6960)
vulnerability in wordpress (CVE-2026-6960). Successful exploitation can lead to full system takeover.
CVE-2026-8134 Vulnerability in concrete5/concrete5 (CVE-2026-8134)
vulnerability in concrete5/concrete5 (CVE-2026-8134). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
CVE-2026-9157 Vulnerability in CVE-2026-9157 (CVE-2026-9157)
vulnerability in CVE-2026-9157 (CVE-2026-9157). Successful exploitation can lead to full system takeover.
CVE-2026-9102 Path Traversal in path-traversal (CVE-2026-9102)
path traversal in path-traversal (CVE-2026-9102). Risk of unauthorized operations or information disclosure.
CVE-2026-45444 Unrestricted File Upload in CVE-2026-45444 (CVE-2026-45444)
vulnerability in CVE-2026-45444 (CVE-2026-45444). Successful exploitation can lead to full system takeover.
CVE-2026-6555 Unrestricted File Upload in wordpress (CVE-2026-6555)
vulnerability in wordpress (CVE-2026-6555). Successful exploitation can lead to full system takeover.
CVE-2026-46426 Unrestricted File Upload in budibase (CVE-2026-46426)
vulnerability in budibase (CVE-2026-46426). Confidential information can be exposed externally. Exploitable via `POST /api/attachments/process`. Mitigation: upgrade to `3.38.2` or later.
CVE-2026-4883 Unrestricted File Upload in wordpress (CVE-2026-4883)
vulnerability in wordpress (CVE-2026-4883). Successful exploitation can lead to full system takeover.
CVE-2026-4885 Unrestricted File Upload in wordpress (CVE-2026-4885)
vulnerability in wordpress (CVE-2026-4885). Successful exploitation can lead to full system takeover.
CVE-2026-27891 FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the f...
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leadin...
CVE-2026-8758 Vulnerability in CVE-2026-8758 (CVE-2026-8758)
vulnerability in CVE-2026-8758 (CVE-2026-8758). Risk of unauthorized operations or information disclosure.
CVE-2020-37227 Unrestricted File Upload in CVE-2020-37227 (CVE-2020-37227)
vulnerability in CVE-2020-37227 (CVE-2020-37227). Successful exploitation can lead to full system takeover.
CVE-2021-47965 Unrestricted File Upload in wordpress (CVE-2021-47965)
vulnerability in wordpress (CVE-2021-47965). Successful exploitation can lead to full system takeover.
CVE-2026-44088 Unrestricted File Upload in CVE-2026-44088 (CVE-2026-44088)
vulnerability in CVE-2026-44088 (CVE-2026-44088). Risk of unauthorized operations or information disclosure.
CVE-2026-45315 Unrestricted File Upload in open-webui (CVE-2026-45315)
vulnerability in open-webui (CVE-2026-45315). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.3` or later.
CVE-2026-41937 Vulnerability in CVE-2026-41937 (CVE-2026-41937)
vulnerability in CVE-2026-41937 (CVE-2026-41937). Successful exploitation can lead to full system takeover.
CVE-2026-22707 Unrestricted File Upload in @strapi/upload (CVE-2026-22707)
vulnerability in @strapi/upload (CVE-2026-22707). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/upload`. Mitigation: upgrade to `5.33.3` or later.
CVE-2026-6271 Unrestricted File Upload in wordpress (CVE-2026-6271)
vulnerability in wordpress (CVE-2026-6271). Successful exploitation can lead to full system takeover.
CVE-2026-45053 Unrestricted File Upload in CVE-2026-45053 (CVE-2026-45053)
vulnerability in CVE-2026-45053 (CVE-2026-45053). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/files`. Mitigation: upgrade to `6.7.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →