Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2021-08-29 CVE-2021-40175 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Log360 5.0/5.1/5.2
Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-08-27 CVE-2020-18114 Unrestricted Upload of File with Dangerous Type vulnerability in Dedecms 5.7
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
network
low complexity
dedecms CWE-434
critical
9.8
2021-08-25 CVE-2021-33884 Unrestricted Upload of File with Dangerous Type vulnerability in Bbraun Spacecom2
An Unrestricted Upload of File with Dangerous Type vulnerability in B.
network
low complexity
bbraun CWE-434
critical
9.1
2021-08-24 CVE-2021-38613 Unrestricted Upload of File with Dangerous Type vulnerability in Nascent Remkon Device Manager 4.0.0.0
The assets/index.php Image Upload feature of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to upload any code to the target system and achieve remote code execution.
network
low complexity
nascent CWE-434
critical
9.8
2021-08-23 CVE-2021-39608 Unrestricted Upload of File with Dangerous Type vulnerability in Flatcore Flatcore-Cms 2.0.7
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
network
low complexity
flatcore CWE-434
7.2
2021-08-20 CVE-2020-27461 Unrestricted Upload of File with Dangerous Type vulnerability in Seopanel 4.6.0
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0.
network
low complexity
seopanel CWE-434
8.8
2021-08-20 CVE-2020-18879 Unrestricted Upload of File with Dangerous Type vulnerability in Bludit 3.8.1
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
network
low complexity
bludit CWE-434
critical
9.8
2021-08-20 CVE-2020-18886 Unrestricted Upload of File with Dangerous Type vulnerability in PHPmywind 5.6
Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'.
network
low complexity
phpmywind CWE-434
7.2
2021-08-18 CVE-2021-37608 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Ofbiz
Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote commands.
network
low complexity
apache CWE-434
critical
9.8
2021-08-16 CVE-2021-22937 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.
network
low complexity
pulsesecure ivanti CWE-434
7.2