Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-04-08 CVE-2022-27061 Unrestricted Upload of File with Dangerous Type vulnerability in Aerocms Project Aerocms 0.0.1
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel.
network
low complexity
aerocms-project CWE-434
7.2
2022-04-08 CVE-2022-27064 Unrestricted Upload of File with Dangerous Type vulnerability in Musical World Project Musical World 1.0
Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php.
network
low complexity
musical-world-project CWE-434
8.8
2022-04-08 CVE-2022-27346 Unrestricted Upload of File with Dangerous Type vulnerability in Ecommerce-Website Project Ecommerce-Website 1.1.0
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides.
network
low complexity
ecommerce-website-project CWE-434
8.8
2022-04-08 CVE-2022-27349 Unrestricted Upload of File with Dangerous Type vulnerability in Socialcodia Social Codia SMS 1.0
Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php.
network
low complexity
socialcodia CWE-434
7.2
2022-04-08 CVE-2022-27351 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul ZOO Management System 1.0
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy.
network
low complexity
phpgurukul CWE-434
critical
9.8
2022-04-08 CVE-2022-27352 Unrestricted Upload of File with Dangerous Type vulnerability in Simple House Rental System Project Simple House Rental System 1.0
Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php.
8.8
2022-04-08 CVE-2022-27357 Unrestricted Upload of File with Dangerous Type vulnerability in Ecommerce-Website Project Ecommerce-Website 1.0
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php.
network
low complexity
ecommerce-website-project CWE-434
critical
9.8
2022-04-07 CVE-2021-43430 Unrestricted Upload of File with Dangerous Type vulnerability in Bigantsoft Bigant Office Messenger 5 5.6
An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.
network
low complexity
bigantsoft CWE-434
8.8
2022-04-07 CVE-2021-43421 Unrestricted Upload of File with Dangerous Type vulnerability in Std42 Elfinder
A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.
network
low complexity
std42 CWE-434
critical
9.8
2022-04-07 CVE-2022-26627 Unrestricted Upload of File with Dangerous Type vulnerability in Online Project Time Management System Project Online Project Time Management System 1.0
Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows attackers to execute arbitrary code via a crafted HTML file.
8.8