Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-05-16 CVE-2022-29354 Unrestricted Upload of File with Dangerous Type vulnerability in Keystonejs Keystone 4.2.1
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.
network
low complexity
keystonejs CWE-434
critical
9.8
2022-05-16 CVE-2022-29622 Unrestricted Upload of File with Dangerous Type vulnerability in Formidable Project Formidable 3.1.4
An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename.
network
low complexity
formidable-project CWE-434
critical
9.8
2022-05-16 CVE-2022-29623 Unrestricted Upload of File with Dangerous Type vulnerability in Connect-Multiparty Project Connect-Multiparty 2.2.0
An arbitrary file upload vulnerability in the file upload module of Connect-Multiparty v2.2.0 allows attackers to execute arbitrary code via a crafted PDF file.
local
low complexity
connect-multiparty-project CWE-434
7.8
2022-05-13 CVE-2021-42967 Unrestricted Upload of File with Dangerous Type vulnerability in Xxyopen Novel-Plus
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
network
low complexity
xxyopen CWE-434
critical
9.8
2022-05-12 CVE-2021-27771 Unrestricted Upload of File with Dangerous Type vulnerability in Hcltech Sametime 11.6
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service.
network
low complexity
hcltech CWE-434
7.6
2022-05-12 CVE-2022-21809 Unrestricted Upload of File with Dangerous Type vulnerability in Inhandnetworks Inrouter302 Firmware 3.5.37/3.5.4
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4.
network
low complexity
inhandnetworks CWE-434
8.1
2022-05-11 CVE-2022-30448 Unrestricted Upload of File with Dangerous Type vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
network
low complexity
hospital-management-system-project CWE-434
critical
9.8
2022-05-11 CVE-2022-29318 Unrestricted Upload of File with Dangerous Type vulnerability in CAR Rental Management System Project CAR Rental Management System 1.0
An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
7.2
2022-05-11 CVE-2022-29655 Unrestricted Upload of File with Dangerous Type vulnerability in Wedding Management System Project Wedding Management System 1.0
An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
7.2
2022-05-11 CVE-2020-19228 Unrestricted Upload of File with Dangerous Type vulnerability in Bludit 3.13.0
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
network
low complexity
bludit CWE-434
7.2