Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-01-25 CVE-2021-46113 Unrestricted Upload of File with Dangerous Type vulnerability in Kea-Hotel-Erp Project Kea-Hotel-Erp
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
network
low complexity
kea-hotel-erp-project CWE-434
8.8
2022-01-21 CVE-2022-22929 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.2.4
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.
network
low complexity
mingsoft CWE-434
critical
9.8
2022-01-21 CVE-2022-23315 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.2.4
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
network
low complexity
mingsoft CWE-434
critical
9.8
2022-01-19 CVE-2021-45808 Unrestricted Upload of File with Dangerous Type vulnerability in Jpress 4.2.0
jpress v4.2.0 allows users to register an account by default.
network
low complexity
jpress CWE-434
8.8
2022-01-18 CVE-2021-46013 Unrestricted Upload of File with Dangerous Type vulnerability in Free School Management Software Project Free School Management Software 1.0
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0.
network
low complexity
free-school-management-software-project CWE-434
critical
9.8
2022-01-18 CVE-2021-38697 Unrestricted Upload of File with Dangerous Type vulnerability in Softvibe Saraban 1.1
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
network
low complexity
softvibe CWE-434
critical
9.8
2022-01-18 CVE-2021-41550 Unrestricted Upload of File with Dangerous Type vulnerability in Leostream Connection Broker 9.0.40.17
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
network
low complexity
leostream CWE-434
7.2
2022-01-15 CVE-2021-33828 Unrestricted Upload of File with Dangerous Type vulnerability in Owncloud Files Antivirus
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
network
low complexity
owncloud CWE-434
8.8
2022-01-13 CVE-2021-34995 Unrestricted Upload of File with Dangerous Type vulnerability in Commvault Commcell 11.22.22
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
network
low complexity
commvault CWE-434
8.8
2022-01-13 CVE-2021-34997 Unrestricted Upload of File with Dangerous Type vulnerability in Commvault Commcell 11.22.22
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
network
low complexity
commvault CWE-434
8.8