Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-09-14 CVE-2022-36667 Unrestricted Upload of File with Dangerous Type vulnerability in Garage Management System Project Garage Management System 1.0
Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function.
network
low complexity
garage-management-system-project CWE-434
8.8
2022-09-14 CVE-2022-37140 Unrestricted Upload of File with Dangerous Type vulnerability in Techvill Paymoney 3.3
PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE).
network
low complexity
techvill CWE-434
8.0
2022-09-13 CVE-2022-38305 Unrestricted Upload of File with Dangerous Type vulnerability in Aerocms Project Aerocms 0.0.1
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php.
network
low complexity
aerocms-project CWE-434
8.8
2022-09-12 CVE-2021-44426 Unrestricted Upload of File with Dangerous Type vulnerability in Anydesk
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5.
network
low complexity
anydesk CWE-434
8.8
2022-09-12 CVE-2022-38296 Unrestricted Upload of File with Dangerous Type vulnerability in Cuppacms 1.0
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
network
low complexity
cuppacms CWE-434
critical
9.8
2022-09-06 CVE-2020-21516 Unrestricted Upload of File with Dangerous Type vulnerability in Feehi Feehicms 2.0.8
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
network
low complexity
feehi CWE-434
critical
9.8
2022-08-31 CVE-2022-36580 Unrestricted Upload of File with Dangerous Type vulnerability in Online Ordering System Project Online Ordering System 2.3.2
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
online-ordering-system-project CWE-434
7.2
2022-08-31 CVE-2022-36582 Unrestricted Upload of File with Dangerous Type vulnerability in Garage Management System Project Garage Management System 1.0
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
garage-management-system-project CWE-434
7.2
2022-08-31 CVE-2022-37184 Unrestricted Upload of File with Dangerous Type vulnerability in Garage Management System Project Garage Management System 1.0
The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload.
network
low complexity
garage-management-system-project CWE-434
8.8
2022-08-29 CVE-2022-36557 Unrestricted Upload of File with Dangerous Type vulnerability in Seiko-Sol products
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function.
network
low complexity
seiko-sol CWE-434
critical
9.8