Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2019-07-10 CVE-2019-0327 Unrestricted Upload of File with Dangerous Type vulnerability in SAP Netweaver Application Server Java
SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (servercode, versions 7.2, 7.3, 7.31, 7.4, 7.5), allows an attacker to upload files (including script files) without proper file format validation.
network
low complexity
sap CWE-434
7.2
2019-07-09 CVE-2019-13464 Unrestricted Upload of File with Dangerous Type vulnerability in Modsecurity Owasp Modsecurity Core Rule SET 3.0.2
An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2.
network
low complexity
modsecurity CWE-434
7.5
2019-07-05 CVE-2019-12971 Unrestricted Upload of File with Dangerous Type vulnerability in G-U BKS EBK Ethernet-Buskoppler PRO Firmware
BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
network
low complexity
g-u CWE-434
critical
9.8
2019-07-04 CVE-2019-13294 Unrestricted Upload of File with Dangerous Type vulnerability in Arox School-Erp
AROX School-ERP Pro has a command execution vulnerability.
network
low complexity
arox CWE-434
critical
9.8
2019-07-02 CVE-2019-7257 Unrestricted Upload of File with Dangerous Type vulnerability in Nortekcontrol products
Linear eMerge E3-Series devices allow Unrestricted File Upload.
network
low complexity
nortekcontrol CWE-434
critical
10.0
2019-07-02 CVE-2019-7268 Unrestricted Upload of File with Dangerous Type vulnerability in Nortekcontrol products
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
network
low complexity
nortekcontrol CWE-434
critical
10.0
2019-07-02 CVE-2019-4292 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Security Guardium 10.5
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server.
network
low complexity
ibm CWE-434
8.8
2019-07-01 CVE-2019-7274 Unrestricted Upload of File with Dangerous Type vulnerability in Optergy Enterprise and Proton
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
network
low complexity
optergy CWE-434
critical
9.8
2019-07-01 CVE-2019-7669 Unrestricted Upload of File with Dangerous Type vulnerability in Primasystems Flexair 2.3.38
Prima Systems FlexAir, Versions 2.3.38 and prior.
network
low complexity
primasystems CWE-434
8.8
2019-06-30 CVE-2019-13082 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo LMS 1.11.8
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature.
network
low complexity
chamilo CWE-434
critical
9.8