Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-03-10 CVE-2023-23328 Unrestricted Upload of File with Dangerous Type vulnerability in Avantfax 3.3.7
A File Upload vulnerability exists in AvantFAX 3.3.7.
network
low complexity
avantfax CWE-434
8.8
2023-03-10 CVE-2023-27164 Unrestricted Upload of File with Dangerous Type vulnerability in Halo
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
network
low complexity
halo CWE-434
4.8
2023-03-08 CVE-2021-33352 Unrestricted Upload of File with Dangerous Type vulnerability in Wyomind Help Desk
An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.
network
low complexity
wyomind CWE-434
critical
9.8
2023-03-08 CVE-2023-22890 Unrestricted Upload of File with Dangerous Type vulnerability in Smartbear Zephyr Enterprise
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.
network
low complexity
smartbear CWE-434
7.5
2023-03-06 CVE-2023-26949 Unrestricted Upload of File with Dangerous Type vulnerability in Onekeyadmin 1.3.9
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
onekeyadmin CWE-434
critical
9.8
2023-03-03 CVE-2023-25402 Unrestricted Upload of File with Dangerous Type vulnerability in Yf-Exam Project Yf-Exam 1.8.0
CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload.
network
low complexity
yf-exam-project CWE-434
7.5
2023-03-01 CVE-2023-20009 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access.
network
low complexity
cisco CWE-434
7.2
2023-03-01 CVE-2023-24045 Unrestricted Upload of File with Dangerous Type vulnerability in Dataiku Data Science Studio
In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.
network
low complexity
dataiku CWE-434
6.5
2023-02-27 CVE-2023-24249 Unrestricted Upload of File with Dangerous Type vulnerability in Laravel-Admin 1.8.19
An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
laravel-admin CWE-434
7.2
2023-02-27 CVE-2023-26762 Unrestricted Upload of File with Dangerous Type vulnerability in Smeup ERP Tokyov6R1M220406
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability.
network
low complexity
smeup CWE-434
8.8