Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-10-03 CVE-2023-44974 Unrestricted Upload of File with Dangerous Type vulnerability in Emlog 2.2.0
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
network
low complexity
emlog CWE-434
critical
9.8
2023-10-03 CVE-2023-4817 Unrestricted Upload of File with Dangerous Type vulnerability in Icpdas Et-7060 Firmware 3.00
This vulnerability allows an authenticated attacker to upload malicious files by bypassing the restrictions of the upload functionality, compromising the entire device.
network
low complexity
icpdas CWE-434
8.8
2023-10-03 CVE-2022-47893 Unrestricted Upload of File with Dangerous Type vulnerability in Riello-Ups Netman 204 Firmware
There is a remote code execution vulnerability that affects all versions of NetMan 204.
network
low complexity
riello-ups CWE-434
critical
9.8
2023-10-03 CVE-2023-4097 Unrestricted Upload of File with Dangerous Type vulnerability in Qsige 3.0.0.0
The file upload functionality is not implemented correctly and allows uploading of any type of file.
network
low complexity
qsige CWE-434
8.8
2023-10-02 CVE-2023-44008 Unrestricted Upload of File with Dangerous Type vulnerability in Mojoportal 2.7.0.0
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.
network
low complexity
mojoportal CWE-434
critical
9.8
2023-10-02 CVE-2023-44009 Unrestricted Upload of File with Dangerous Type vulnerability in Mojoportal 2.7.0.0
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.
network
low complexity
mojoportal CWE-434
critical
9.8
2023-09-28 CVE-2023-5185 Unrestricted Upload of File with Dangerous Type vulnerability in Projectworlds GYM Management System Project 1.0
Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
network
low complexity
projectworlds CWE-434
8.8
2023-09-28 CVE-2023-43226 Unrestricted Upload of File with Dangerous Type vulnerability in Dedecms
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
network
low complexity
dedecms CWE-434
8.8
2023-09-28 CVE-2022-47186 Unrestricted Upload of File with Dangerous Type vulnerability in Generex Cs141 Firmware
There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version.
network
low complexity
generex CWE-434
critical
9.1
2023-09-28 CVE-2023-38874 Unrestricted Upload of File with Dangerous Type vulnerability in Economizzer 0.9/April2023
A remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023).
network
low complexity
economizzer CWE-434
8.8