Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2020-05-29 CVE-2020-12675 Unrestricted Upload of File with Dangerous Type vulnerability in Mappresspro Mappress
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution.
network
low complexity
mappresspro CWE-434
8.8
2020-05-25 CVE-2020-13442 Unrestricted Upload of File with Dangerous Type vulnerability in Dext5 2.7.1402870
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870.
network
low complexity
dext5 CWE-434
critical
9.8
2020-05-22 CVE-2020-13384 Unrestricted Upload of File with Dangerous Type vulnerability in Monstra 3.0.4
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, for example, .php filenames are blocked but .php7 filenames are not, a related issue to CVE-2017-18048.
network
low complexity
monstra CWE-434
8.8
2020-05-21 CVE-2020-1112 Unrestricted Upload of File with Dangerous Type vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
network
low complexity
microsoft CWE-434
critical
9.9
2020-05-21 CVE-2020-1102 Unrestricted Upload of File with Dangerous Type vulnerability in Microsoft Sharepoint Enterprise Server and Sharepoint Server
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-434
8.8
2020-05-21 CVE-2020-1024 Unrestricted Upload of File with Dangerous Type vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-434
8.8
2020-05-21 CVE-2020-1023 Unrestricted Upload of File with Dangerous Type vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-434
8.8
2020-05-21 CVE-2020-12828 Unrestricted Upload of File with Dangerous Type vulnerability in Pango Virtual Private Network Software Development KIT
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218.
network
low complexity
pango CWE-434
critical
9.8
2020-05-20 CVE-2020-13241 Unrestricted Upload of File with Dangerous Type vulnerability in Microweber 1.1.18
Microweber 1.1.18 allows Unrestricted File Upload because admin/view:modules/load_module:users#edit-user=1 does not verify that the file extension (used with the Add Image option on the Edit User screen) corresponds to an image file.
local
low complexity
microweber CWE-434
7.8
2020-05-19 CVE-2020-11807 Unrestricted Upload of File with Dangerous Type vulnerability in Sourcefabric Newscoop 4.4.7
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path.
local
low complexity
sourcefabric CWE-434
7.8