Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-04-10 CVE-2022-27129 Unrestricted Upload of File with Dangerous Type vulnerability in Zbzcms 1.0
An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
zbzcms CWE-434
7.5
2022-04-10 CVE-2022-27131 Unrestricted Upload of File with Dangerous Type vulnerability in Zbzcms 1.0
An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
zbzcms CWE-434
7.5
2022-04-10 CVE-2022-27477 Unrestricted Upload of File with Dangerous Type vulnerability in Newbee-Mall Project Newbee-Mall 1.0
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
network
low complexity
newbee-mall-project CWE-434
7.5
2022-04-08 CVE-2022-27047 Unrestricted Upload of File with Dangerous Type vulnerability in Moguit Mogu Blog CMS 5.2
mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.
network
low complexity
moguit CWE-434
7.5
2022-04-08 CVE-2021-46367 Unrestricted Upload of File with Dangerous Type vulnerability in Ritecms 1.0/1.0.0/2.2.1
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel.
network
low complexity
ritecms CWE-434
critical
9.0
2022-04-08 CVE-2022-27061 Unrestricted Upload of File with Dangerous Type vulnerability in Aerocms Project Aerocms 0.0.1
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel.
network
low complexity
aerocms-project CWE-434
6.5
2022-04-08 CVE-2022-27064 Unrestricted Upload of File with Dangerous Type vulnerability in Musical World Project Musical World 1.0
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php.
network
low complexity
musical-world-project CWE-434
6.5
2022-04-08 CVE-2022-27346 Unrestricted Upload of File with Dangerous Type vulnerability in Ecommerce-Website Project Ecommerce-Website 1.1.0
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides.
network
low complexity
ecommerce-website-project CWE-434
6.5
2022-04-08 CVE-2022-27349 Unrestricted Upload of File with Dangerous Type vulnerability in Socialcodia Social Codia SMS 1.0
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php.
network
low complexity
socialcodia CWE-434
6.5
2022-04-08 CVE-2022-27351 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul ZOO Management System 1.0
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy.
network
low complexity
phpgurukul CWE-434
critical
9.8