Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-06-05 CVE-2020-19028 Unrestricted Upload of File with Dangerous Type vulnerability in Emlog 6.0.0
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function.
network
low complexity
emlog CWE-434
7.5
2023-06-05 CVE-2023-29631 Unrestricted Upload of File with Dangerous Type vulnerability in Joommasters JMS Slider 1.6.0
PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.
network
low complexity
joommasters CWE-434
critical
9.8
2023-06-05 CVE-2023-33386 Unrestricted Upload of File with Dangerous Type vulnerability in Marsctf Project Marsctf 1.2.1
MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.
network
low complexity
marsctf-project CWE-434
critical
9.8
2023-06-02 CVE-2023-3032 Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web Application 06.7.22
Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modules) allows a malicious user to Upload a Web Shell to a Web Server.This issue affects Mobatime web application: through 06.7.22.
network
low complexity
mobatime CWE-434
8.8
2023-06-02 CVE-2023-2063 Unrestricted Upload of File with Dangerous Type vulnerability in Mitsubishielectric products
Unrestricted Upload of File with Dangerous Type vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to cause information disclosure, tampering, deletion or destruction via file upload/download.
network
low complexity
mitsubishielectric CWE-434
7.3
2023-05-31 CVE-2023-33508 Unrestricted Upload of File with Dangerous Type vulnerability in Kramerav VIA GO2 Firmware
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
network
low complexity
kramerav CWE-434
critical
9.8
2023-05-31 CVE-2023-28353 Unrestricted Upload of File with Dangerous Type vulnerability in Faronics Insight 10.0.19045
An issue was discovered in Faronics Insight 10.0.19045 on Windows.
low complexity
faronics CWE-434
8.8
2023-05-30 CVE-2023-32689 Unrestricted Upload of File with Dangerous Type vulnerability in Parseplatform Parse-Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-434
6.5
2023-05-25 CVE-2023-22504 Unrestricted Upload of File with Dangerous Type vulnerability in Atlassian Confluence Server
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
network
low complexity
atlassian CWE-434
6.5
2023-05-24 CVE-2023-29721 Unrestricted Upload of File with Dangerous Type vulnerability in Sofawiki Project Sofawiki 3.8.9
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
network
low complexity
sofawiki-project CWE-434
critical
9.8