Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2024-02-22 CVE-2024-25802 Unrestricted Upload of File with Dangerous Type vulnerability in Skinsoft S-Museum 7.02.3
SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function.
network
low complexity
skinsoft CWE-434
critical
9.8
2024-02-19 CVE-2024-25636 Unrestricted Upload of File with Dangerous Type vulnerability in Misskey
Misskey is an open source, decentralized social media platform with ActivityPub support.
network
low complexity
misskey CWE-434
8.8
2024-02-19 CVE-2024-25623 Unrestricted Upload of File with Dangerous Type vulnerability in Joinmastodon Mastodon
Mastodon is a free, open-source social network server based on ActivityPub.
network
low complexity
joinmastodon CWE-434
7.7
2024-02-16 CVE-2024-25414 Unrestricted Upload of File with Dangerous Type vulnerability in Cszcms CSZ CMS 1.3.0
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.
network
low complexity
cszcms CWE-434
critical
9.8
2024-02-12 CVE-2024-23759 Unrestricted Upload of File with Dangerous Type vulnerability in Gambio 4.9.2.0
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
network
low complexity
gambio CWE-434
critical
9.8
2024-02-12 CVE-2024-23762 Unrestricted Upload of File with Dangerous Type vulnerability in Gambio 4.9.2.0
Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.
local
low complexity
gambio CWE-434
7.8
2024-02-09 CVE-2024-25674 Unrestricted Upload of File with Dangerous Type vulnerability in Misp
An issue was discovered in MISP before 2.4.184.
network
low complexity
misp CWE-434
critical
9.8
2024-02-08 CVE-2023-25365 Unrestricted Upload of File with Dangerous Type vulnerability in Octobercms October 3.2.0
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3
local
low complexity
octobercms CWE-434
7.8
2024-02-08 CVE-2023-40265 Unrestricted Upload of File with Dangerous Type vulnerability in Mitel Unify Openscape Xpressions Webassistant
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911.
network
low complexity
mitel CWE-434
8.8
2024-02-08 CVE-2024-24393 Unrestricted Upload of File with Dangerous Type vulnerability in Oaooa Pichome 1.1.01
File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.
network
low complexity
oaooa CWE-434
critical
9.8