Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-02-03 CVE-2021-36426 Unrestricted Upload of File with Dangerous Type vulnerability in PHPwcms
File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to include/inc_lib/general.inc.php.
network
low complexity
phpwcms CWE-434
8.8
2023-02-02 CVE-2022-46604 Unrestricted Upload of File with Dangerous Type vulnerability in Tecrail Responsive Filemanager
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.
network
low complexity
tecrail CWE-434
8.8
2023-02-01 CVE-2023-23135 Unrestricted Upload of File with Dangerous Type vulnerability in Ftdms Project Ftdms 3.1.6
An arbitrary file upload vulnerability in Ftdms v3.1.6 allows attackers to execute arbitrary code via uploading a crafted JPG file.
network
low complexity
ftdms-project CWE-434
7.2
2023-02-01 CVE-2023-24610 Unrestricted Upload of File with Dangerous Type vulnerability in Nosh Chartingsystem Project Nosh Chartingsystem 20210313
NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature.
network
low complexity
nosh-chartingsystem-project CWE-434
8.8
2023-02-01 CVE-2022-42971 Unrestricted Upload of File with Dangerous Type vulnerability in Schneider-Electric products
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file.
network
low complexity
schneider-electric CWE-434
critical
9.8
2023-02-01 CVE-2023-0587 Unrestricted Upload of File with Dangerous Type vulnerability in Trendmicro Apex ONE
A file upload vulnerability in exists in Trend Micro Apex One server build 11110.
network
low complexity
trendmicro CWE-434
critical
9.1
2023-02-01 CVE-2022-47769 Unrestricted Upload of File with Dangerous Type vulnerability in Serinf Fast Checkin 1.0
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.
network
low complexity
serinf CWE-434
critical
9.8
2023-01-31 CVE-2022-47854 Unrestricted Upload of File with Dangerous Type vulnerability in I-Librarian 4.10
i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.
network
low complexity
i-librarian CWE-434
critical
9.8
2023-01-30 CVE-2022-48006 Unrestricted Upload of File with Dangerous Type vulnerability in Taogogo Taocms 3.0.2
An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
taogogo CWE-434
critical
9.8
2023-01-27 CVE-2021-41231 Unrestricted Upload of File with Dangerous Type vulnerability in Openmage Magento
OpenMage LTS is an e-commerce platform.
network
low complexity
openmage CWE-434
7.2