Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2024-07-15 CVE-2024-5630 Unrestricted Upload of File with Dangerous Type vulnerability in Elearningfreak Insert or Embed Articulate Content
The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
network
low complexity
elearningfreak CWE-434
8.8
2024-07-12 CVE-2024-40545 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
publiccms CWE-434
8.8
2024-07-12 CVE-2024-40546 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
publiccms CWE-434
8.8
2024-07-12 CVE-2024-40548 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
publiccms CWE-434
8.8
2024-07-12 CVE-2024-40549 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
publiccms CWE-434
8.8
2024-07-12 CVE-2024-40550 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
publiccms CWE-434
8.8
2024-07-12 CVE-2024-40551 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
publiccms CWE-434
8.8
2024-07-12 CVE-2024-3112 Unrestricted Upload of File with Dangerous Type vulnerability in Bestwebsoft Quotes and Tips
The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
network
low complexity
bestwebsoft CWE-434
4.8
2024-07-10 CVE-2023-7061 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager File Manager Advanced Shortcode 2.3.2/2.5.3
The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3.
network
low complexity
advancedfilemanager CWE-434
8.8
2024-07-09 CVE-2024-39865 Unrestricted Upload of File with Dangerous Type vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).
network
low complexity
siemens CWE-434
8.8