Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2024-08-29 CVE-2024-8295 Unrestricted Upload of File with Dangerous Type vulnerability in Feehi Feehicms
A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical.
network
low complexity
feehi CWE-434
critical
9.8
2024-08-29 CVE-2024-8294 Unrestricted Upload of File with Dangerous Type vulnerability in Feehi Feehicms
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1.
network
low complexity
feehi CWE-434
critical
9.8
2024-08-28 CVE-2024-6311 Unrestricted Upload of File with Dangerous Type vulnerability in Funnelforms Free
The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions up to, and including, 3.7.3.2.
network
low complexity
funnelforms CWE-434
7.2
2024-08-26 CVE-2024-8170 Unrestricted Upload of File with Dangerous Type vulnerability in Rems Zipped Folder Manager APP 1.0
A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0.
network
low complexity
rems CWE-434
critical
9.8
2024-08-26 CVE-2024-8166 Unrestricted Upload of File with Dangerous Type vulnerability in Ruijie Eg2000K Firmware 11.1(6)B2
A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical.
network
low complexity
ruijie CWE-434
4.9
2024-08-26 CVE-2024-8164 Unrestricted Upload of File with Dangerous Type vulnerability in Beikeshop
A vulnerability, which was classified as critical, has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5.
network
low complexity
beikeshop CWE-434
8.8
2024-08-23 CVE-2024-8089 Unrestricted Upload of File with Dangerous Type vulnerability in Janobe E-Commerce System 1.0
A vulnerability was found in SourceCodester E-Commerce System 1.0.
network
low complexity
janobe CWE-434
critical
9.8
2024-08-22 CVE-2024-39717 Unrestricted Upload of File with Dangerous Type vulnerability in Versa-Networks Versa Director
The Versa Director GUI provides an option to customize the look and feel of the user interface.
network
low complexity
versa-networks CWE-434
7.2
2024-08-22 CVE-2024-7384 Unrestricted Upload of File with Dangerous Type vulnerability in Acymailing
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the acym_extractArchive function in all versions up to, and including, 9.7.2.
network
low complexity
acymailing CWE-434
8.8
2024-08-21 CVE-2024-42777 Unrestricted Upload of File with Dangerous Type vulnerability in Lopalopa Music Management System 1.0
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
network
low complexity
lopalopa CWE-434
critical
9.8