Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2021-02-01 CVE-2021-3378 Unrestricted Upload of File with Dangerous Type vulnerability in Fortilogger
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.
network
low complexity
fortilogger CWE-434
critical
9.8
2021-02-01 CVE-2020-20287 Unrestricted Upload of File with Dangerous Type vulnerability in Yccms 3.3
Unrestricted file upload vulnerability in the yccms 3.3 project.
network
low complexity
yccms CWE-434
critical
9.8
2021-01-26 CVE-2021-3164 Unrestricted Upload of File with Dangerous Type vulnerability in Churchdesk Churchrota 2.6.4
ChurchRota 2.6.4 is vulnerable to authenticated remote code execution.
network
low complexity
churchdesk CWE-434
8.8
2021-01-26 CVE-2020-24549 Unrestricted Upload of File with Dangerous Type vulnerability in Openmaint
openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.
network
low complexity
openmaint CWE-434
8.8
2021-01-26 CVE-2020-22643 Unrestricted Upload of File with Dangerous Type vulnerability in Feehi CMS 2.1.0
Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution.
network
low complexity
feehi CWE-434
7.2
2021-01-21 CVE-2020-26295 Unrestricted Upload of File with Dangerous Type vulnerability in Openmage
OpenMage is a community-driven alternative to Magento CE.
network
low complexity
openmage CWE-434
7.2
2021-01-20 CVE-2020-19364 Unrestricted Upload of File with Dangerous Type vulnerability in Open-Emr Openemr 5.0.1
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
network
low complexity
open-emr CWE-434
8.8
2021-01-19 CVE-2020-29450 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature.
network
low complexity
atlassian CWE-434
6.5
2021-01-18 CVE-2021-3166 Unrestricted Upload of File with Dangerous Type vulnerability in Asus Dsl-N14U B1 Firmware 1.1.2.3805
An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices.
network
low complexity
asus CWE-434
7.5
2021-01-07 CVE-2019-18643 Unrestricted Upload of File with Dangerous Type vulnerability in Sparkdevnetwork Rock RMS
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application.
network
low complexity
sparkdevnetwork CWE-434
critical
9.8