Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-12-08 CVE-2022-46828 Unrestricted Upload of File with Dangerous Type vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
local
low complexity
jetbrains CWE-434
7.8
2022-12-07 CVE-2022-45009 Unrestricted Upload of File with Dangerous Type vulnerability in Online Leave Management System Project Online Leave Management System 1.0
Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=update_settings.
7.2
2022-12-06 CVE-2022-45548 Unrestricted Upload of File with Dangerous Type vulnerability in Ayacms Project Ayacms 3.1.2
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
network
low complexity
ayacms-project CWE-434
8.8
2022-12-06 CVE-2022-44289 Unrestricted Upload of File with Dangerous Type vulnerability in Thinkphp 5.0.24/5.1.41
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
network
low complexity
thinkphp CWE-434
8.8
2022-12-05 CVE-2022-45912 Unrestricted Upload of File with Dangerous Type vulnerability in Zimbra Collaboration 8.8.15/9.0.0
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.
network
low complexity
zimbra CWE-434
7.2
2022-12-03 CVE-2022-4276 Unrestricted Upload of File with Dangerous Type vulnerability in House Rental System Project House Rental System
A vulnerability was found in House Rental System and classified as critical.
network
low complexity
house-rental-system-project CWE-434
critical
9.8
2022-12-03 CVE-2022-4273 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Human Resource Management System 1.0
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0.
network
low complexity
oretnom23 CWE-434
critical
9.8
2022-12-01 CVE-2022-36431 Unrestricted Upload of File with Dangerous Type vulnerability in Rocketsoftware Trufusion
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file.
network
low complexity
rocketsoftware CWE-434
critical
9.8
2022-11-30 CVE-2022-4232 Unrestricted Upload of File with Dangerous Type vulnerability in Rinvizle Event Registration System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0.
network
low complexity
rinvizle CWE-434
critical
9.8
2022-11-29 CVE-2022-44354 Unrestricted Upload of File with Dangerous Type vulnerability in Contec Solarview Compact Firmware 4.0/5.0
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
network
low complexity
contec CWE-434
critical
9.8