Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-04-01 CVE-2022-23155 Unrestricted Upload of File with Dangerous Type vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability.
network
low complexity
dell CWE-434
7.2
2022-03-31 CVE-2021-34257 Unrestricted Upload of File with Dangerous Type vulnerability in Wpanel CMS Project Wpanel CMS
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
network
low complexity
wpanel-cms-project CWE-434
8.8
2022-03-31 CVE-2022-24136 Unrestricted Upload of File with Dangerous Type vulnerability in Hospital Management System Project Hospital Management System 1.0
Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php.
network
low complexity
hospital-management-system-project CWE-434
critical
9.8
2022-03-30 CVE-2022-26645 Unrestricted Upload of File with Dangerous Type vulnerability in Banking System Project Banking System 1.0
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
network
low complexity
banking-system-project CWE-434
critical
9.8
2022-03-30 CVE-2022-28223 Unrestricted Upload of File with Dangerous Type vulnerability in Tekon products
Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.
network
low complexity
tekon CWE-434
7.2
2022-03-29 CVE-2021-45865 Unrestricted Upload of File with Dangerous Type vulnerability in Student Attendance Management System Project Student Attendance Management System 1.0
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.
network
low complexity
student-attendance-management-system-project CWE-434
critical
9.8
2022-03-28 CVE-2021-43098 Unrestricted Upload of File with Dangerous Type vulnerability in Diyhi BBS 5.3
A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.
network
low complexity
diyhi CWE-434
7.2
2022-03-28 CVE-2021-43100 Unrestricted Upload of File with Dangerous Type vulnerability in Diyhi BBS 5.3
A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
network
low complexity
diyhi CWE-434
7.2
2022-03-28 CVE-2021-43101 Unrestricted Upload of File with Dangerous Type vulnerability in Diyhi BBS 5.3
A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
network
low complexity
diyhi CWE-434
7.2
2022-03-28 CVE-2021-43102 Unrestricted Upload of File with Dangerous Type vulnerability in Diyhi BBS 5.3
A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.
network
low complexity
diyhi CWE-434
7.2