Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-07-05 CVE-2022-32413 Unrestricted Upload of File with Dangerous Type vulnerability in Dice Project Dice 4.2.0
An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
network
low complexity
dice-project CWE-434
critical
9.8
2022-07-01 CVE-2022-31943 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.2.8
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
network
low complexity
mingsoft CWE-434
critical
9.8
2022-06-30 CVE-2021-37770 Unrestricted Upload of File with Dangerous Type vulnerability in Nucleuscms Nucleus CMS 3.71
Nucleus CMS v3.71 is affected by a file upload vulnerability.
network
low complexity
nucleuscms CWE-434
7.2
2022-06-27 CVE-2022-32994 Unrestricted Upload of File with Dangerous Type vulnerability in Halo 1.5.3
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
network
low complexity
halo CWE-434
critical
9.8
2022-06-27 CVE-2022-31086 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g.
network
low complexity
ldap-account-manager debian CWE-434
8.8
2022-06-27 CVE-2022-2212 Unrestricted Upload of File with Dangerous Type vulnerability in Library Management System Project Library Management System 1.0
A vulnerability was found in SourceCodester Library Management System 1.0.
8.8
2022-06-24 CVE-2021-38945 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation.
network
low complexity
ibm netapp CWE-434
critical
9.8
2022-06-24 CVE-2013-1916 Unrestricted Upload of File with Dangerous Type vulnerability in User Photo Project User Photo 0.9.4
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress.
network
low complexity
user-photo-project CWE-434
8.8
2022-06-24 CVE-2022-2102 Unrestricted Upload of File with Dangerous Type vulnerability in Secheron Sepcos Control and Protection Relay Firmware 1.23.0/1.24.0/1.25.0
Controls limiting uploads to certain file extensions may be bypassed.
network
low complexity
secheron CWE-434
7.5
2022-06-23 CVE-2021-40954 Unrestricted Upload of File with Dangerous Type vulnerability in Laiketui 3.5.0
Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.
network
low complexity
laiketui CWE-434
critical
9.8