Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-11-18 CVE-2022-42698 Unrestricted Upload of File with Dangerous Type vulnerability in Api2Cart Bridge Connector 1.0.0/1.1.0
Unauth.
network
low complexity
api2cart CWE-434
critical
9.8
2022-11-17 CVE-2022-40200 Unrestricted Upload of File with Dangerous Type vulnerability in Gvectors Wpforo Forum
Auth.
network
low complexity
gvectors CWE-434
8.8
2022-11-17 CVE-2022-43192 Unrestricted Upload of File with Dangerous Type vulnerability in Dedecms 5.7.101
An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code via a crafted PHP file.
local
low complexity
dedecms CWE-434
6.7
2022-11-17 CVE-2022-44384 Unrestricted Upload of File with Dangerous Type vulnerability in Rconfig 3.9.6
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
rconfig CWE-434
8.8
2022-11-16 CVE-2022-43234 Unrestricted Upload of File with Dangerous Type vulnerability in Hoosk 1.8.0
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
hoosk CWE-434
critical
9.8
2022-11-15 CVE-2022-43265 Unrestricted Upload of File with Dangerous Type vulnerability in Canteen Management System Project Canteen Management System 1.0
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
canteen-management-system-project CWE-434
critical
9.8
2022-11-14 CVE-2022-43146 Unrestricted Upload of File with Dangerous Type vulnerability in Canteen Management System Project Canteen Management System 1.0
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
7.2
2022-11-11 CVE-2022-3944 Unrestricted Upload of File with Dangerous Type vulnerability in ERP Project ERP
A vulnerability was found in jerryhanjj ERP.
network
low complexity
erp-project CWE-434
8.8
2022-11-10 CVE-2022-40981 Unrestricted Upload of File with Dangerous Type vulnerability in Etictelecom Remote Access Server Firmware 4.5.0
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload.
network
low complexity
etictelecom CWE-434
critical
10.0
2022-11-10 CVE-2022-43074 Unrestricted Upload of File with Dangerous Type vulnerability in Ayacms Project Ayacms 3.1.2
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php.
network
low complexity
ayacms-project CWE-434
critical
9.8