Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-10-17 CVE-2022-42029 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo 1.11.16
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.
network
low complexity
chamilo CWE-434
8.8
2022-10-17 CVE-2022-42154 Unrestricted Upload of File with Dangerous Type vulnerability in 74Cms 74Cmsse 3.13.0
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
74cms CWE-434
critical
9.8
2022-10-17 CVE-2022-3549 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Simple Cold Storage Management System 1.0
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0.
network
low complexity
oretnom23 CWE-434
7.2
2022-10-14 CVE-2022-32177 Unrestricted Upload of File with Dangerous Type vulnerability in Gin-Vue-Admin Project Gin-Vue-Admin
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library.
network
low complexity
gin-vue-admin-project CWE-434
critical
9.0
2022-10-14 CVE-2022-41538 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-14 CVE-2022-41539 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-13 CVE-2022-41533 Unrestricted Upload of File with Dangerous Type vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php.
7.2
2022-10-13 CVE-2022-41534 Unrestricted Upload of File with Dangerous Type vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php.
7.2
2022-10-12 CVE-2022-3458 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Human Resource Management System 1.0
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical.
network
low complexity
oretnom23 CWE-434
critical
9.8
2022-10-12 CVE-2022-40921 Unrestricted Upload of File with Dangerous Type vulnerability in Dedecms 5.7.99
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.
network
low complexity
dedecms CWE-434
7.2