Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2024-06-18 CVE-2024-6084 Unrestricted Upload of File with Dangerous Type vulnerability in Janobe Pool of Bethesda Online Reservation System 1.0
A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical.
network
low complexity
janobe CWE-434
critical
9.8
2024-06-18 CVE-2024-6083 Unrestricted Upload of File with Dangerous Type vulnerability in PHPvibe 11.0.46
A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46.
network
low complexity
phpvibe CWE-434
critical
9.8
2024-06-14 CVE-2024-3912 Certain models of ASUS routers have an arbitrary firmware upload vulnerability.
network
low complexity
CWE-434
critical
9.8
2024-06-14 CVE-2024-31161 Unrestricted Upload of File with Dangerous Type vulnerability in Asus Download Master
The upload functionality of ASUS Download Master does not properly filter user input.
network
low complexity
asus CWE-434
7.2
2024-06-13 CVE-2024-36396 Unrestricted Upload of File with Dangerous Type vulnerability in Verint Workforce Optimization
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type
network
low complexity
verint CWE-434
8.8
2024-06-13 CVE-2024-34110 Unrestricted Upload of File with Dangerous Type vulnerability in Adobe Commerce and Magento
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution.
network
low complexity
adobe CWE-434
7.2
2024-06-12 CVE-2024-1659 Unrestricted Upload of File with Dangerous Type vulnerability in Megabip 4.36.2
Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This issue affects MegaBIP software versions through 5.10.
network
low complexity
megabip CWE-434
critical
9.8
2024-06-11 CVE-2024-34683 Unrestricted Upload of File with Dangerous Type vulnerability in SAP Document Builder
An authenticated attacker can upload malicious file to SAP Document Builder service.
network
low complexity
sap CWE-434
6.5
2024-06-10 CVE-2024-36415 Unrestricted Upload of File with Dangerous Type vulnerability in Salesagility Suitecrm
SuiteCRM is an open-source Customer Relationship Management (CRM) software application.
network
low complexity
salesagility CWE-434
8.8
2024-06-10 CVE-2024-35746 Unrestricted Upload of File with Dangerous Type vulnerability in Buddypress Cover Project Buddypress Cover 2.1.4.2
Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects BuddyPress Cover: from n/a through 2.1.4.2.
network
low complexity
buddypress-cover-project CWE-434
critical
9.8