Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-08-31 CVE-2022-36582 Unrestricted Upload of File with Dangerous Type vulnerability in Garage Management System Project Garage Management System 1.0
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
garage-management-system-project CWE-434
7.2
2022-08-31 CVE-2022-37184 Unrestricted Upload of File with Dangerous Type vulnerability in Garage Management System Project Garage Management System 1.0
The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload.
network
low complexity
garage-management-system-project CWE-434
8.8
2022-08-29 CVE-2022-36557 Unrestricted Upload of File with Dangerous Type vulnerability in Seiko-Sol products
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function.
network
low complexity
seiko-sol CWE-434
critical
9.8
2022-08-25 CVE-2022-37159 Unrestricted Upload of File with Dangerous Type vulnerability in Claroline
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
network
low complexity
claroline CWE-434
critical
9.8
2022-08-24 CVE-2022-37181 Unrestricted Upload of File with Dangerous Type vulnerability in 72Crm Wukong CRM 9.0
72crm 9.0 has an Arbitrary file upload vulnerability.
network
low complexity
72crm CWE-434
critical
9.8
2022-08-22 CVE-2021-29891 Unrestricted Upload of File with Dangerous Type vulnerability in IBM products
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services.
network
low complexity
ibm CWE-434
4.9
2022-08-22 CVE-2022-35150 Unrestricted Upload of File with Dangerous Type vulnerability in Baijiacms Project Baijiacms 41420170105
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
network
low complexity
baijiacms-project CWE-434
critical
9.8
2022-08-22 CVE-2022-2594 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedcustomfields Advanced Custom Fields
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available.
network
low complexity
advancedcustomfields CWE-434
8.8
2022-08-11 CVE-2022-2750 Unrestricted Upload of File with Dangerous Type vulnerability in Company Website CMS Project Company Website CMS
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS.
network
low complexity
company-website-cms-project CWE-434
critical
9.8
2022-08-10 CVE-2022-35426 Unrestricted Upload of File with Dangerous Type vulnerability in Ucms Project Ucms 1.6
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
network
low complexity
ucms-project CWE-434
critical
9.8