Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-05-05 CVE-2023-30122 Unrestricted Upload of File with Dangerous Type vulnerability in Online Food Ordering System Project Online Food Ordering System 2.0
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
network
low complexity
online-food-ordering-system-project CWE-434
critical
9.8
2023-05-04 CVE-2023-30264 Unrestricted Upload of File with Dangerous Type vulnerability in Cltphp 6.0
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.
network
low complexity
cltphp CWE-434
critical
9.8
2023-05-04 CVE-2023-2523 Unrestricted Upload of File with Dangerous Type vulnerability in E-Office 9.5
A vulnerability was found in Weaver E-Office 9.5.
network
low complexity
e-office CWE-434
critical
9.8
2023-05-02 CVE-2022-47878 Unrestricted Upload of File with Dangerous Type vulnerability in Jedox 2020.2.5
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory.
network
low complexity
jedox CWE-434
8.8
2023-05-01 CVE-2023-29635 Unrestricted Upload of File with Dangerous Type vulnerability in Antabot White-Jotter Project Antabot White-Jotter 0.2.2
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload.
network
low complexity
antabot-white-jotter-project CWE-434
critical
9.8
2023-04-28 CVE-2023-24269 Unrestricted Upload of File with Dangerous Type vulnerability in Textpattern 4.8.8
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.
network
low complexity
textpattern CWE-434
8.8
2023-04-26 CVE-2023-29268 Unrestricted Upload of File with Dangerous Type vulnerability in Tibco Spotfire Statistics Services
The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system.
network
low complexity
tibco CWE-434
critical
9.8
2023-04-26 CVE-2022-25277 Unrestricted Upload of File with Dangerous Type vulnerability in Drupal
Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010).
network
low complexity
drupal CWE-434
7.2
2023-04-26 CVE-2023-30266 Unrestricted Upload of File with Dangerous Type vulnerability in Cltphp 6.0
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
network
low complexity
cltphp CWE-434
8.8
2023-04-26 CVE-2022-36769 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cloud PAK for Data 4.5/4.6
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment.
network
low complexity
ibm CWE-434
7.2