Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2025-04-18 CVE-2025-3783 Unrestricted Upload of File with Dangerous Type vulnerability in Seniorwalter Web-Based Pharmacy Product Management System 1.0
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0.
network
low complexity
seniorwalter CWE-434
critical
9.8
2025-04-17 CVE-2025-3764 A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0.
network
low complexity
CWE-434
6.3
2025-04-17 CVE-2025-3765 A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0.
network
low complexity
CWE-434
6.3
2025-04-14 CVE-2025-3593 A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0.
network
low complexity
CWE-434
6.3
2025-04-14 CVE-2025-3565 A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0.
network
low complexity
CWE-434
4.7
2025-04-14 CVE-2025-3558 A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0.
network
low complexity
CWE-434
6.3
2025-04-08 CVE-2025-2525 The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_Authentication_Controller::edit_profile' function in all versions up to, and including, 4.0.1.
network
low complexity
CWE-434
8.8
2025-04-06 CVE-2025-3324 Unrestricted Upload of File with Dangerous Type vulnerability in Godcheese Nimrod 0.8
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8.
network
low complexity
godcheese CWE-434
8.8
2025-04-06 CVE-2025-32370 Unrestricted Upload of File with Dangerous Type vulnerability in Kentico Xperience
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions.
network
low complexity
kentico CWE-434
critical
9.8
2025-04-05 CVE-2025-1500 IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.
network
low complexity
CWE-434
5.5