Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-06-23 CVE-2022-31362 Unrestricted Upload of File with Dangerous Type vulnerability in Docebo 4.0.5
Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability.
network
low complexity
docebo CWE-434
8.8
2022-06-21 CVE-2022-31374 Unrestricted Upload of File with Dangerous Type vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.
network
low complexity
contec CWE-434
critical
9.8
2022-06-20 CVE-2017-20063 Unrestricted Upload of File with Dangerous Type vulnerability in Elefantcms Elefant CMS 1.3.12
A vulnerability was found in Elefant CMS 1.3.12-RC.
network
low complexity
elefantcms CWE-434
8.8
2022-06-16 CVE-2021-41421 Unrestricted Upload of File with Dangerous Type vulnerability in Maianmedia Maianaffiliate 1.0
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel.
network
low complexity
maianmedia CWE-434
4.8
2022-06-15 CVE-2022-32433 Unrestricted Upload of File with Dangerous Type vulnerability in Advanced School Management System Project Advanced School Management System 1.0
itsourcecode Advanced School Management System v1.0 is vulnerable to Arbitrary code execution via ip/school/view/all_teacher.php.
7.2
2022-06-15 CVE-2021-40940 Unrestricted Upload of File with Dangerous Type vulnerability in Monstra
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
network
low complexity
monstra CWE-434
critical
9.8
2022-06-14 CVE-2021-42675 Unrestricted Upload of File with Dangerous Type vulnerability in Kreado Kreasfero 1.5
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory.
network
low complexity
kreado CWE-434
critical
9.8
2022-06-09 CVE-2017-20021 Unrestricted Upload of File with Dangerous Type vulnerability in Solar-Log products
A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85.
network
low complexity
solar-log CWE-434
critical
9.8
2022-06-07 CVE-2021-35532 Unrestricted Upload of File with Dangerous Type vulnerability in Hitachienergy Txpert HUB Coretec 4 Firmware
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product.
local
low complexity
hitachienergy CWE-434
6.7
2022-06-06 CVE-2022-30860 Unrestricted Upload of File with Dangerous Type vulnerability in Fudforum
FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.
network
low complexity
fudforum CWE-434
7.2