Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-10-11 CVE-2022-42038 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Ip-Addresses 0.1.0
The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42039 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Lists 0.1.0
The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42040 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Algorithms 0.1.0
The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42043 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Xml 0.1.0
The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42044 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Asns 0.1.0
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42034 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-11 CVE-2022-42229 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-09 CVE-2022-3436 Unrestricted Upload of File with Dangerous Type vulnerability in Web-Based Student Clearance System Project Web-Based Student Clearance System 1.0
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0.
7.5
2022-10-07 CVE-2022-41379 Unrestricted Upload of File with Dangerous Type vulnerability in Online Leave Management System Project Online Leave Management System 1.0
An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
7.2
2022-10-07 CVE-2022-41512 Unrestricted Upload of File with Dangerous Type vulnerability in Online Diagnostic LAB Management System Project Online Diagnostic LAB Management System 1.0
An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
7.2