Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-09-29 CVE-2022-36066 Unrestricted Upload of File with Dangerous Type vulnerability in Discourse
Discourse is an open source discussion platform.
network
low complexity
discourse CWE-434
7.2
2022-09-29 CVE-2022-40407 Unrestricted Upload of File with Dangerous Type vulnerability in Chamilo 1.11
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
network
low complexity
chamilo CWE-434
8.8
2022-09-29 CVE-2021-45790 Unrestricted Upload of File with Dangerous Type vulnerability in Metersphere 1.15.4
An arbitrary file upload vulnerability was found in Metersphere v1.15.4.
network
low complexity
metersphere CWE-434
critical
9.8
2022-09-29 CVE-2022-40048 Unrestricted Upload of File with Dangerous Type vulnerability in Flatpress 1.2.1
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
network
low complexity
flatpress CWE-434
7.2
2022-09-27 CVE-2022-37346 Unrestricted Upload of File with Dangerous Type vulnerability in Ec-Cube Product Image Bulk Upload 1.0.0/4.1.0
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files.
network
low complexity
ec-cube CWE-434
critical
9.8
2022-09-27 CVE-2022-40878 Unrestricted Upload of File with Dangerous Type vulnerability in Exam Reviewer Management System Project Exam Reviewer Management System 1.0
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
8.8
2022-09-26 CVE-2022-40050 Unrestricted Upload of File with Dangerous Type vulnerability in Zfile 4.1.1
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
network
low complexity
zfile CWE-434
critical
9.8
2022-09-26 CVE-2022-40924 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul ZOO Management System 1.0
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.
network
low complexity
phpgurukul CWE-434
7.2
2022-09-26 CVE-2022-40925 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul ZOO Management System 1.0
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.
network
low complexity
phpgurukul CWE-434
7.2
2022-09-22 CVE-2022-40932 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul ZOO Management System 1.0
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.
network
low complexity
phpgurukul CWE-434
7.2