Vulnerabilities (CVE)

Filtered by CWE-434
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-33615 1 Rsa 1 Archer 2022-06-09 8.5 HIGH 7.5 HIGH
RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.
CVE-2022-29637 1 Iminho 1 Mindoc 2022-06-08 6.8 MEDIUM 7.8 HIGH
An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafted Zip file.
CVE-2022-29632 1 Roncoo 1 Roncoo-education 2022-06-08 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-28062 1 Online Car Rental System Project 1 Online Car Rental System 2022-06-05 6.5 MEDIUM 8.8 HIGH
Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.
CVE-2021-42654 1 Sscms 1 Siteserver Cms 2022-06-03 7.5 HIGH 9.8 CRITICAL
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
CVE-2022-29651 1 Online Food Ordering System Project 1 Online Food Ordering System 2022-06-03 6.5 MEDIUM 7.2 HIGH
An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-1837 1 Home Clean Services Management System Project 1 Home Clean Services Management System 2022-06-02 6.5 MEDIUM 7.2 HIGH
A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.
CVE-2022-28104 2 Apple, Foxit 2 Iphone Os, Pdf Editor 2022-06-02 7.5 HIGH 9.8 CRITICAL
Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-29622 1 Formidable Project 1 Formidable 2022-06-02 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled.
CVE-2021-38697 1 Softvibe 1 Saraban 2022-06-01 7.5 HIGH 9.8 CRITICAL
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
CVE-2022-28927 1 Subconverter Project 1 Subconverter 2022-05-26 7.5 HIGH 9.8 CRITICAL
A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters.
CVE-2022-1752 1 Trudesk Project 1 Trudesk 2022-05-26 6.0 MEDIUM 8.0 HIGH
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-30887 1 Pharmacy Management System Project 1 Pharmacy Management System 2022-05-26 7.5 HIGH 9.8 CRITICAL
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CVE-2021-41938 1 Shopxo 1 Shopxo 2022-05-26 6.5 MEDIUM 7.2 HIGH
An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.
CVE-2022-1103 1 Advanced Uploader Project 1 Advanced Uploader 2022-05-26 6.5 MEDIUM 8.8 HIGH
The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE
CVE-2022-30007 1 Gxcms Project 1 Gxcms 2022-05-26 6.5 MEDIUM 7.2 HIGH
GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server.
CVE-2022-22482 1 Ibm 1 Sterling B2b Integrator 2022-05-26 4.0 MEDIUM 6.5 MEDIUM
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenticated user to upload files that could fill up the filesystem and cause a denial of service. IBM X-Force ID: 225977.
CVE-2021-25119 1 Wpsocket 1 Automatic Grid Image Listing 2022-05-25 6.5 MEDIUM 7.2 HIGH
The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE
CVE-2021-33009 1 Myscada 1 Mypro 2022-05-24 5.0 MEDIUM 7.5 HIGH
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.
CVE-2022-29623 1 Connect-multiparty Project 1 Connect-multiparty 2022-05-24 6.8 MEDIUM 7.8 HIGH
An arbitrary file upload vulnerability in the file upload module of Connect-Multiparty v2.2.0 allows attackers to execute arbitrary code via a crafted PDF file.
CVE-2021-27771 1 Hcltech 1 Sametime 2022-05-24 6.5 MEDIUM 7.6 HIGH
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.
CVE-2021-42171 1 Tribalsystems 1 Zenario 2022-05-24 6.5 MEDIUM 7.2 HIGH
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
CVE-2022-29354 1 Keystonejs 1 Keystone 2022-05-24 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-29353 1 Graphql-upload Project 1 Graphql-upload 2022-05-24 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename.
CVE-2022-29351 1 Tiddlywiki 1 Tiddlywiki5 2022-05-24 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file.
CVE-2021-42967 1 Novel-plus Project 1 Novel-plus 2022-05-24 7.5 HIGH 9.8 CRITICAL
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
CVE-2020-8162 2 Debian, Rubyonrails 2 Debian Linux, Rails 2022-05-24 5.0 MEDIUM 7.5 HIGH
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.
CVE-2022-1409 1 Vikwp 1 Hotel Booking Engine \& Pms 2022-05-24 6.5 MEDIUM 7.2 HIGH
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code
CVE-2022-21809 1 Inhandnetworks 2 Inrouter302, Inrouter302 Firmware 2022-05-23 5.5 MEDIUM 8.1 HIGH
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.
CVE-2022-30448 1 Hospital Management System Project 1 Hospital Management System 2022-05-20 7.5 HIGH 9.8 CRITICAL
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
CVE-2020-19228 1 Bludit 1 Bludit 2022-05-18 9.0 HIGH 7.2 HIGH
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
CVE-2022-29318 1 Car Rental Management System Project 1 Car Rental Management System 2022-05-17 6.5 MEDIUM 7.2 HIGH
An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-29655 1 Wedding Management System Project 1 Wedding Management System 2022-05-17 6.5 MEDIUM 7.2 HIGH
An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2021-42645 1 Cmsimple-xh 1 Cmsimple Xh 2022-05-16 10.0 HIGH 10.0 CRITICAL
CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.
CVE-2021-37194 1 Siemens 1 Comos 2022-05-13 5.0 MEDIUM 7.5 HIGH
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS allows to upload and store arbitrary files at the webserver. This could allow an attacker to store malicious files.
CVE-2022-28606 1 Bosscms 1 Bosscms 2022-05-13 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.
CVE-2022-28120 1 Rainier 1 Open Virtual Simulation Experiment Teaching Management Platform 2022-05-13 7.5 HIGH 9.8 CRITICAL
Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.
CVE-2022-1411 1 Yetiforce 1 Yetiforce Customer Relationship Management 2022-05-12 4.3 MEDIUM 6.1 MEDIUM
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.
CVE-2022-28695 1 F5 1 Big-ip Advanced Firewall Manager 2022-05-12 6.5 MEDIUM 7.2 HIGH
On F5 BIG-IP AFM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, an authenticated attacker with high privileges can upload a maliciously crafted file to the BIG-IP AFM Configuration utility, which allows an attacker to run arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVE-2022-29347 1 Web\@rchiv Project 1 Web\@rchiv 2022-05-12 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
CVE-2022-28568 1 Simple Doctor\'s Appointment System Project 1 Simple Doctor\'s Appointment System 2022-05-12 7.5 HIGH 9.8 CRITICAL
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
CVE-2022-29451 1 Rarathemes 1 Rara One Click Demo Import 2022-05-11 6.8 MEDIUM 8.8 HIGH
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
CVE-2022-29001 1 Springbootmovie Project 1 Springbootmovie 2022-05-10 6.5 MEDIUM 7.2 HIGH
In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability
CVE-2022-1273 1 Importwp 1 Import Wp 2022-05-10 6.5 MEDIUM 7.2 HIGH
The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege users such as admin to upload arbitrary files (such as PHP), leading to RCE
CVE-2022-20743 1 Cisco 1 Firepower Management Center 2022-05-09 9.0 HIGH 8.8 HIGH
A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to bypass security protections and upload malicious files to the affected system. This vulnerability is due to improper validation of files uploaded to the web management interface of Cisco FMC Software. An attacker could exploit this vulnerability by uploading a maliciously crafted file to a device running affected software. A successful exploit could allow the attacker to store malicious files on the device, which they could access later to conduct additional attacks, including executing arbitrary code on the affected device with root privileges.
CVE-2021-43934 1 Smartptt 1 Smartptt Scada 2022-05-09 7.5 HIGH 9.8 CRITICAL
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.
CVE-2021-41921 1 Novel-plus Project 1 Novel-plus 2022-05-06 7.5 HIGH 9.8 CRITICAL
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
CVE-2022-27468 1 Monstaftp 1 Monsta Ftp 2022-05-05 7.5 HIGH 9.8 CRITICAL
Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.
CVE-2022-28528 1 Bloofox 1 Bloofoxcms 2022-05-05 6.5 MEDIUM 8.8 HIGH
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
CVE-2022-28053 1 Typemill 1 Typemill 2022-05-05 6.5 MEDIUM 8.8 HIGH
Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.