Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-06-16 CVE-2021-41421 Unrestricted Upload of File with Dangerous Type vulnerability in Maianmedia Maianaffiliate 1.0
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.
network
low complexity
maianmedia CWE-434
4.8
2022-06-15 CVE-2022-32433 Unrestricted Upload of File with Dangerous Type vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to Arbitrary code execution via ip/school/view/all_teacher.php.
7.2
2022-06-15 CVE-2021-40940 Unrestricted Upload of File with Dangerous Type vulnerability in Monstra
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
network
low complexity
monstra CWE-434
critical
9.8
2022-06-14 CVE-2021-42675 Unrestricted Upload of File with Dangerous Type vulnerability in Kreado Kreasfero 1.5
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory.
network
low complexity
kreado CWE-434
critical
9.8
2022-06-09 CVE-2017-20021 Unrestricted Upload of File with Dangerous Type vulnerability in Solar-Log products
A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85.
network
low complexity
solar-log CWE-434
critical
9.8
2022-06-07 CVE-2021-35532 Unrestricted Upload of File with Dangerous Type vulnerability in Hitachienergy Txpert HUB Coretec 4 Firmware
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product.
local
low complexity
hitachienergy CWE-434
6.7
2022-06-06 CVE-2022-30860 Unrestricted Upload of File with Dangerous Type vulnerability in Fudforum
FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.
network
low complexity
fudforum CWE-434
7.2
2022-06-02 CVE-2021-45982 Unrestricted Upload of File with Dangerous Type vulnerability in Netscout Ngeniusone 6.3.2
NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.
network
low complexity
netscout CWE-434
8.8
2022-06-02 CVE-2022-32019 Unrestricted Upload of File with Dangerous Type vulnerability in CAR Rental Management System Project CAR Rental Management System 1.0
Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.
network
low complexity
car-rental-management-system-project CWE-434
critical
9.8
2022-06-02 CVE-2021-26634 Unrestricted Upload of File with Dangerous Type vulnerability in Maxb Maxboard
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation.
network
low complexity
maxb CWE-434
critical
9.8