Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2020-02-24 CVE-2020-5188 Unrestricted Upload of File with Dangerous Type vulnerability in Dnnsoftware Dotnetnuke
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
network
low complexity
dnnsoftware CWE-434
6.5
2020-02-20 CVE-2020-9320 Unrestricted Upload of File with Dangerous Type vulnerability in Avira products
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive.
local
low complexity
avira CWE-434
5.5
2020-02-17 CVE-2015-0258 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
network
low complexity
o-dyn debian canonical CWE-434
8.8
2020-02-12 CVE-2020-6975 Unrestricted Upload of File with Dangerous Type vulnerability in Digi products
Digi International ConnectPort LTS 32 MEI, Firmware Version 1.4.3 (82002228_K 08/09/2018), bios Version 1.2.
network
low complexity
digi CWE-434
4.9
2020-02-12 CVE-2011-4908 Unrestricted Upload of File with Dangerous Type vulnerability in Tiny Tinybrowser
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
network
low complexity
tiny CWE-434
critical
9.8
2020-02-12 CVE-2011-4906 Unrestricted Upload of File with Dangerous Type vulnerability in Tiny Tinybrowser
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
network
low complexity
tiny CWE-434
critical
9.8
2020-02-11 CVE-2013-3684 Unrestricted Upload of File with Dangerous Type vulnerability in Imagely Nextgen Gallery
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
network
low complexity
imagely CWE-434
critical
9.8
2020-02-11 CVE-2013-2057 Unrestricted Upload of File with Dangerous Type vulnerability in Yabb 2.5.2
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
network
low complexity
yabb CWE-434
critical
9.8
2020-02-11 CVE-2013-0803 Unrestricted Upload of File with Dangerous Type vulnerability in Polarbear CMS Project Polarbear CMS 2.5
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
network
low complexity
polarbear-cms-project CWE-434
critical
9.8
2020-02-10 CVE-2019-20451 Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Prismview Player 11 and Prismview System 9
The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC.
network
low complexity
samsung CWE-434
critical
9.8