Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2021-42645 Unrestricted Upload of File with Dangerous Type vulnerability in Cmsimple-Xh Cmsimple XH 1.7.4
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability.
network
low complexity
cmsimple-xh CWE-434
critical
10.0
2022-05-05 CVE-2022-28120 Unrestricted Upload of File with Dangerous Type vulnerability in Rainier Open Virtual Simulation Experiment Teaching Management Platform 2.0
Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.
network
low complexity
rainier CWE-434
critical
9.8
2022-05-05 CVE-2022-28606 Unrestricted Upload of File with Dangerous Type vulnerability in Bosscms 1.0.0
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd.
network
low complexity
bosscms CWE-434
critical
9.8
2022-05-05 CVE-2022-1411 Unrestricted Upload of File with Dangerous Type vulnerability in Yetiforce Customer Relationship Management
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
network
low complexity
yetiforce CWE-434
6.1
2022-05-04 CVE-2022-28568 Unrestricted Upload of File with Dangerous Type vulnerability in Simple Doctor'S Appointment System Project Simple Doctor'S Appointment System 1.0
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel.
network
low complexity
simple-doctor-s-appointment-system-project CWE-434
critical
9.8
2022-05-04 CVE-2022-29347 Unrestricted Upload of File with Dangerous Type vulnerability in Web@Rchiv Project Web@Rchiv 1.0
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
network
low complexity
web-rchiv-project CWE-434
critical
9.8
2022-05-03 CVE-2022-29001 Unrestricted Upload of File with Dangerous Type vulnerability in Springbootmovie Project Springbootmovie 1.0/1.1/1.2
In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability
network
low complexity
springbootmovie-project CWE-434
7.2
2022-05-03 CVE-2022-20743 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system.
network
low complexity
cisco CWE-434
8.8
2022-04-28 CVE-2021-41921 Unrestricted Upload of File with Dangerous Type vulnerability in Xxyopen Novel-Plus 3.6.1
novel-plus V3.6.1 allows unrestricted file uploads.
network
low complexity
xxyopen CWE-434
critical
9.8
2022-04-26 CVE-2022-28525 Unrestricted Upload of File with Dangerous Type vulnerability in Ed01-Cms Project Ed01-Cms 20180505
ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.
network
low complexity
ed01-cms-project CWE-434
8.8