Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2022-01-12 CVE-2021-45411 Unrestricted Upload of File with Dangerous Type vulnerability in Printable Staff ID Card Creator System Project Printable Staff ID Card Creator System 1.0
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
9.8
2022-01-12 CVE-2021-44651 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Log360 and Manageengine Cloud Security Plus
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
network
low complexity
zohocorp CWE-434
8.8
2022-01-11 CVE-2021-43973 Unrestricted Upload of File with Dangerous Type vulnerability in Sysaid 20.4.74
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body.
network
low complexity
sysaid CWE-434
8.8
2022-01-06 CVE-2021-46078 Unrestricted Upload of File with Dangerous Type vulnerability in Vehicle Service Management System Project Vehicle Service Management System
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0.
4.8
2022-01-06 CVE-2021-46079 Unrestricted Upload of File with Dangerous Type vulnerability in Vehicle Service Management System Project Vehicle Service Management System
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0.
7.2
2022-01-06 CVE-2021-46076 Unrestricted Upload of File with Dangerous Type vulnerability in Vehicle Service Management System Project Vehicle Service Management System 1.0
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload.
8.8
2021-12-22 CVE-2021-44031 Unrestricted Upload of File with Dangerous Type vulnerability in Quest Kace Desktop Authority
An issue was discovered in Quest KACE Desktop Authority before 11.2.
network
low complexity
quest CWE-434
critical
9.8
2021-12-20 CVE-2021-35244 Unrestricted Upload of File with Dangerous Type vulnerability in Solarwinds Orion Platform
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file.
network
low complexity
solarwinds CWE-434
7.2
2021-12-17 CVE-2021-23814 Unrestricted Upload of File with Dangerous Type vulnerability in Unisharp Laravel-Filemanager
This affects the package unisharp/laravel-filemanager from 0.0.0.
network
low complexity
unisharp CWE-434
8.8
2021-12-15 CVE-2021-41560 Unrestricted Upload of File with Dangerous Type vulnerability in Opencats
OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.
network
low complexity
opencats CWE-434
critical
9.8