Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-05-04 CVE-2023-2523 Unrestricted Upload of File with Dangerous Type vulnerability in E-Office 9.5
A vulnerability was found in Weaver E-Office 9.5.
network
low complexity
e-office CWE-434
critical
9.8
2023-05-02 CVE-2022-47878 Unrestricted Upload of File with Dangerous Type vulnerability in Jedox 2020.2.5
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory.
network
low complexity
jedox CWE-434
8.8
2023-05-01 CVE-2023-29635 Unrestricted Upload of File with Dangerous Type vulnerability in Antabot White-Jotter Project Antabot White-Jotter 0.2.2
File upload vulnerability in Antabot White-Jotter v0.2.2, allows remote attackers to execute malicious code via the file parameter to function coversUpload.
network
low complexity
antabot-white-jotter-project CWE-434
critical
9.8
2023-04-28 CVE-2023-24269 Unrestricted Upload of File with Dangerous Type vulnerability in Textpattern 4.8.8
An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.
network
low complexity
textpattern CWE-434
8.8
2023-04-26 CVE-2023-29268 Unrestricted Upload of File with Dangerous Type vulnerability in Tibco Spotfire Statistics Services
The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system.
network
low complexity
tibco CWE-434
critical
9.8
2023-04-26 CVE-2022-25277 Unrestricted Upload of File with Dangerous Type vulnerability in Drupal
Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading and trailing dots from filenames to prevent uploading server configuration files (reference: SA-CORE-2019-010).
network
low complexity
drupal CWE-434
7.2
2023-04-26 CVE-2023-30266 Unrestricted Upload of File with Dangerous Type vulnerability in Cltphp 6.0
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type.
network
low complexity
cltphp CWE-434
8.8
2023-04-26 CVE-2022-36769 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Cloud PAK for Data 4.5/4.6
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment.
network
low complexity
ibm CWE-434
7.2
2023-04-25 CVE-2023-26098 Unrestricted Upload of File with Dangerous Type vulnerability in Telindus Apsal 3.14.2022.235B
An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b.
local
low complexity
telindus CWE-434
7.8
2023-04-24 CVE-2023-25132 Unrestricted Upload of File with Dangerous Type vulnerability in Cyberpower Powerpanel 4.8.6
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to execute operation system commands via unspecified vectors.
network
low complexity
cyberpower CWE-434
critical
9.8