Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-20073 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device.
network
low complexity
cisco CWE-434
critical
9.8
2023-04-05 CVE-2023-26857 Unrestricted Upload of File with Dangerous Type vulnerability in Dynamic Transaction Queuing System Project Dynamic Transaction Queuing System 1.0
An arbitrary file upload vulnerability in /admin/ajax.php?action=save_uploads of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
7.2
2023-04-04 CVE-2023-0265 Unrestricted Upload of File with Dangerous Type vulnerability in Uvdesk Community-Skeleton 1.1.1
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server.
network
low complexity
uvdesk CWE-434
8.8
2023-04-04 CVE-2021-31707 Unrestricted Upload of File with Dangerous Type vulnerability in Kitesky Kitecms
Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.
network
low complexity
kitesky CWE-434
critical
9.8
2023-04-04 CVE-2021-3267 Unrestricted Upload of File with Dangerous Type vulnerability in Kitesky Kitecms 1.1
File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.
network
low complexity
kitesky CWE-434
7.2
2023-04-04 CVE-2023-26775 Unrestricted Upload of File with Dangerous Type vulnerability in Monitorr 1.7.6M
File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint.
local
low complexity
monitorr CWE-434
7.8
2023-04-02 CVE-2023-1800 Unrestricted Upload of File with Dangerous Type vulnerability in Go-Fastdfs Project Go-Fastdfs
A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3.
network
low complexity
go-fastdfs-project CWE-434
critical
9.8
2023-04-02 CVE-2023-1797 Unrestricted Upload of File with Dangerous Type vulnerability in Otcms 6.01
A vulnerability classified as critical was found in OTCMS 6.0.1.
network
low complexity
otcms CWE-434
critical
9.8
2023-03-31 CVE-2022-47190 Unrestricted Upload of File with Dangerous Type vulnerability in Generex Cs141 Firmware
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute arbitrary code as root.
network
low complexity
generex CWE-434
critical
9.8
2023-03-31 CVE-2022-47191 Unrestricted Upload of File with Dangerous Type vulnerability in Generex Cs141 Firmware
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing him to escalate privileges.
network
low complexity
generex CWE-434
8.8