Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2024-05-14 CVE-2024-27943 Unrestricted Upload of File with Dangerous Type vulnerability in Siemens Ruggedcom Crossbow 5.2/5.3/5.4
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5).
network
low complexity
siemens CWE-434
7.2
2024-05-14 CVE-2024-27944 Unrestricted Upload of File with Dangerous Type vulnerability in Siemens Ruggedcom Crossbow 5.2/5.3/5.4
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5).
network
low complexity
siemens CWE-434
7.2
2024-05-14 CVE-2024-27945 Unrestricted Upload of File with Dangerous Type vulnerability in Siemens Ruggedcom Crossbow 5.2/5.3/5.4
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5).
network
low complexity
siemens CWE-434
7.2
2024-05-02 CVE-2024-1567 Unrestricted Upload of File with Dangerous Type vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94.
network
low complexity
royal-elementor-addons CWE-434
critical
9.8
2024-04-10 CVE-2024-31214 Unrestricted Upload of File with Dangerous Type vulnerability in Traccar
Traccar is an open source GPS tracking system.
network
low complexity
traccar CWE-434
critical
9.6
2024-03-31 CVE-2023-46808 Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Neurons for Itsm
An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server.
network
low complexity
ivanti CWE-434
critical
9.9
2024-03-25 CVE-2024-28105 Unrestricted Upload of File with Dangerous Type vulnerability in PHPmyfaq 3.2.5
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases.
network
low complexity
phpmyfaq CWE-434
7.2
2024-03-21 CVE-2024-27923 Unrestricted Upload of File with Dangerous Type vulnerability in Getgrav Grav
Grav is a content management system (CMS).
network
low complexity
getgrav CWE-434
8.8
2024-03-20 CVE-2023-51444 Unrestricted Upload of File with Dangerous Type vulnerability in Geoserver
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
network
low complexity
geoserver CWE-434
7.2
2024-02-29 CVE-2024-25832 Unrestricted Upload of File with Dangerous Type vulnerability in F-Logic Datacube3 1.0
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.
network
low complexity
f-logic CWE-434
8.8