Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-02-23 CVE-2023-24317 Unrestricted Upload of File with Dangerous Type vulnerability in Judging Management System Project Judging Management System 1.0
Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.
8.1
2023-02-22 CVE-2022-39983 Unrestricted Upload of File with Dangerous Type vulnerability in Instantdeveloper RD3 22.0.8500
File upload vulnerability in Instantdeveloper RD3 22.0.8500, allows attackers to execute arbitrary code.
network
low complexity
instantdeveloper CWE-434
critical
9.8
2023-02-22 CVE-2022-41217 Unrestricted Upload of File with Dangerous Type vulnerability in Hybridsoftware Cloudflow 2.0.0/2.3.1
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
network
low complexity
hybridsoftware CWE-434
critical
9.8
2023-02-22 CVE-2022-2883 Unrestricted Upload of File with Dangerous Type vulnerability in Octopus Server
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
network
low complexity
octopus CWE-434
7.5
2023-02-17 CVE-2021-35261 Unrestricted Upload of File with Dangerous Type vulnerability in Bearadmin Project Bearadmin
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.
network
low complexity
bearadmin-project CWE-434
critical
9.8
2023-02-14 CVE-2023-22937 Unrestricted Upload of File with Dangerous Type vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup tables with unnecessary filename extensions.
network
low complexity
splunk CWE-434
4.3
2023-02-13 CVE-2023-24646 Unrestricted Upload of File with Dangerous Type vulnerability in Online Food Ordering System Project Online Food Ordering System 2.0
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
online-food-ordering-system-project CWE-434
critical
9.8
2023-02-13 CVE-2023-0255 Unrestricted Upload of File with Dangerous Type vulnerability in Shortpixel Enable Media Replace
The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
network
low complexity
shortpixel CWE-434
8.8
2023-02-08 CVE-2022-45527 Unrestricted Upload of File with Dangerous Type vulnerability in Institutional Management Website Project Institutional Management Website 1.0
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
network
low complexity
institutional-management-website-project CWE-434
critical
9.8
2023-02-06 CVE-2023-24202 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Raffle Draw System 1.0
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.
network
low complexity
oretnom23 CWE-434
critical
9.8