Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-10-11 CVE-2022-42036 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Urls 0.1.0
The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42037 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Asns 0.1.0
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42038 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Ip-Addresses 0.1.0
The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42039 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Lists 0.1.0
The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42040 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Algorithms 0.1.0
The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42043 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Xml 0.1.0
The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42044 Unrestricted Upload of File with Dangerous Type vulnerability in Democritus D8S-Asns 0.1.0
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
network
low complexity
democritus CWE-434
critical
9.8
2022-10-11 CVE-2022-42034 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-11 CVE-2022-42229 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Planner Project Wedding Planner 1.0
Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.
network
low complexity
wedding-planner-project CWE-434
8.8
2022-10-09 CVE-2022-3436 Unrestricted Upload of File with Dangerous Type vulnerability in Web-Based Student Clearance System Project Web-Based Student Clearance System 1.0
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0.
7.5