Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-05-23 CVE-2023-27397 Unrestricted Upload of File with Dangerous Type vulnerability in Microengine Mailform
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8.
network
low complexity
microengine CWE-434
critical
9.8
2023-05-23 CVE-2023-28409 Unrestricted Upload of File with Dangerous Type vulnerability in MW WP Form Project MW WP Form 4.4.2
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.
network
low complexity
mw-wp-form-project CWE-434
critical
9.8
2023-05-22 CVE-2023-31689 Unrestricted Upload of File with Dangerous Type vulnerability in Wcms 0.3.2
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter.
network
low complexity
wcms CWE-434
critical
9.8
2023-05-18 CVE-2023-30333 Unrestricted Upload of File with Dangerous Type vulnerability in Perfree Perfreeblog 3.1.2
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
network
low complexity
perfree CWE-434
critical
9.8
2023-05-17 CVE-2023-31903 Unrestricted Upload of File with Dangerous Type vulnerability in Freeguppy Guppy 6.00.10
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
network
low complexity
freeguppy CWE-434
critical
9.8
2023-05-16 CVE-2023-31857 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Online Computer and Laptop Store 1.0
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.
network
low complexity
oretnom23 CWE-434
critical
9.8
2023-05-16 CVE-2023-31576 Unrestricted Upload of File with Dangerous Type vulnerability in S9Y Serendipity 2.4.0
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
network
low complexity
s9y CWE-434
8.8
2023-05-12 CVE-2023-30247 Unrestricted Upload of File with Dangerous Type vulnerability in Storage Unit Rental Management System Project Storage Unit Rental Management System 1.0
File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.
network
low complexity
storage-unit-rental-management-system-project CWE-434
critical
9.8
2023-05-12 CVE-2023-29657 Unrestricted Upload of File with Dangerous Type vulnerability in Extplorer 2.1.15
eXtplorer 2.1.15 is vulnerable to Insecure Permissions.
network
low complexity
extplorer CWE-434
8.8
2023-05-11 CVE-2021-34076 Unrestricted Upload of File with Dangerous Type vulnerability in PHPok 5.7.140
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
network
low complexity
phpok CWE-434
8.8