Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2024-01-19 CVE-2024-0713 Unrestricted Upload of File with Dangerous Type vulnerability in Monitorr 1.7.6M
A vulnerability was found in Monitorr 1.7.6m.
network
low complexity
monitorr CWE-434
8.8
2024-01-18 CVE-2023-40051 Unrestricted Upload of File with Dangerous Type vulnerability in Progress Openedge and Openedge Innovation
This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE.
network
low complexity
progress CWE-434
critical
9.9
2024-01-17 CVE-2024-0648 Unrestricted Upload of File with Dangerous Type vulnerability in Yunyou CMS Project Yunyou CMS
A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical.
network
low complexity
yunyou-cms-project CWE-434
critical
9.8
2024-01-17 CVE-2024-0643 Unrestricted Upload of File with Dangerous Type vulnerability in Cires21 Live Encoder 5.3
Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3.
network
low complexity
cires21 CWE-434
critical
9.8
2024-01-16 CVE-2022-1538 Unrestricted Upload of File with Dangerous Type vulnerability in Themely Theme Demo Import
Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.
network
low complexity
themely CWE-434
7.2
2024-01-16 CVE-2023-4536 Unrestricted Upload of File with Dangerous Type vulnerability in Koalaapps MY Account Page Editor
The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE
network
low complexity
koalaapps CWE-434
8.8
2024-01-15 CVE-2023-50729 Unrestricted Upload of File with Dangerous Type vulnerability in Traccar
Traccar is an open source GPS tracking system.
network
low complexity
traccar CWE-434
critical
9.8
2024-01-13 CVE-2024-0505 Unrestricted Upload of File with Dangerous Type vulnerability in Zhongfucheng3Y Austin 1.0
A vulnerability was found in ZhongFuCheng3y Austin 1.0 and classified as critical.
network
low complexity
zhongfucheng3y CWE-434
critical
9.8
2024-01-12 CVE-2024-0468 Unrestricted Upload of File with Dangerous Type vulnerability in Code-Projects Fighting Cock Information System 1.0
A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical.
network
low complexity
code-projects CWE-434
critical
9.8
2024-01-12 CVE-2023-51806 Unrestricted Upload of File with Dangerous Type vulnerability in Ujcms 8.0.2
File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.
network
low complexity
ujcms CWE-434
5.4