Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2019-09-23 CVE-2019-16720 Unrestricted Upload of File with Dangerous Type vulnerability in Zzzcms Zzzphp 1.7.2
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
network
low complexity
zzzcms CWE-434
7.5
2019-09-20 CVE-2015-9402 Unrestricted Upload of File with Dangerous Type vulnerability in Usersultra Users Ultra Membership
The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
network
low complexity
usersultra CWE-434
8.8
2019-09-20 CVE-2019-14916 Unrestricted Upload of File with Dangerous Type vulnerability in Prise Adas 1.7.0
An issue was discovered in PRiSE adAS 1.7.0.
network
low complexity
prise CWE-434
6.5
2019-09-18 CVE-2019-14252 Unrestricted Upload of File with Dangerous Type vulnerability in Publisure 2.1.2
An issue was discovered in the secure portal in Publisure 2.1.2.
network
low complexity
publisure CWE-434
7.2
2019-09-18 CVE-2019-15843 Unrestricted Upload of File with Dangerous Type vulnerability in MI Xiaomi Millet Firmware 16.3.9.3
A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3.
network
high complexity
mi CWE-434
7.4
2019-09-18 CVE-2016-10995 Unrestricted Upload of File with Dangerous Type vulnerability in Templatic Telvolution
The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
network
low complexity
templatic CWE-434
critical
9.8
2019-09-17 CVE-2019-6839 Unrestricted Upload of File with Dangerous Type vulnerability in Schneider-Electric products
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to upload a rogue file.
network
low complexity
schneider-electric CWE-434
8.8
2019-09-17 CVE-2019-15131 Unrestricted Upload of File with Dangerous Type vulnerability in Code42
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed.
network
low complexity
code42 CWE-434
critical
9.8
2019-09-16 CVE-2019-8371 Unrestricted Upload of File with Dangerous Type vulnerability in Open-Emr Openemr 5.0.16
OpenEMR v5.0.1-6 allows code execution.
network
low complexity
open-emr CWE-434
7.2
2019-09-16 CVE-2016-10959 Unrestricted Upload of File with Dangerous Type vulnerability in Estatik
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.
network
low complexity
estatik CWE-434
6.5