Total
2765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-27757 | 1 Perfree | 1 Perfreeblog | 2023-03-17 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. | |||||
CVE-2023-1313 | 1 Agentejo | 1 Cockpit | 2023-03-15 | N/A | 8.8 HIGH |
Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1. | |||||
CVE-2023-26949 | 1 Onekeyadmin | 1 Onekeyadmin | 2023-03-13 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2023-24249 | 1 Laravel-admin | 1 Laravel-admin | 2023-03-07 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2021-35290 | 1 Balero Cms Project | 1 Balero Cms | 2023-03-07 | N/A | 7.2 HIGH |
File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /admin/main/mod-blog page. | |||||
CVE-2021-33224 | 1 Umbraco | 1 Umbraco Forms | 2023-03-06 | N/A | 9.8 CRITICAL |
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file. | |||||
CVE-2023-26762 | 1 Smeup | 1 Erp | 2023-03-04 | N/A | 8.8 HIGH |
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability. | |||||
CVE-2023-24317 | 1 Judging Management System Project | 1 Judging Management System | 2023-03-03 | N/A | 8.1 HIGH |
Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php. | |||||
CVE-2022-2111 | 1 Inventree Project | 1 Inventree | 2023-02-28 | 6.5 MEDIUM | 8.8 HIGH |
Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2. | |||||
CVE-2019-12803 | 1 Hunesion | 1 I-onenet | 2023-02-28 | 10.0 HIGH | 9.8 CRITICAL |
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as running a system command. | |||||
CVE-2016-10954 | 1 Dynamicpress | 1 Neosense | 2023-02-23 | 7.5 HIGH | 9.8 CRITICAL |
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. | |||||
CVE-2012-1592 | 1 Apache | 1 Struts | 2023-02-13 | 6.5 MEDIUM | 8.8 HIGH |
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. | |||||
CVE-2021-34427 | 1 Eclipse | 1 Business Intelligence And Reporting Tools | 2023-02-11 | 7.5 HIGH | 9.8 CRITICAL |
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance. | |||||
CVE-2020-12675 | 1 Mappresspro | 1 Mappress | 2023-02-09 | 6.5 MEDIUM | 8.8 HIGH |
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an incomplete fix for CVE-2020-12077. | |||||
CVE-2020-12077 | 1 Mappresspro | 1 Mappress | 2023-02-09 | 6.5 MEDIUM | 8.8 HIGH |
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution. | |||||
CVE-2022-0537 | 1 Mappresspro | 1 Mappress | 2023-02-09 | 6.5 MEDIUM | 7.2 HIGH |
The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet directory, and a .php file extension is added. No validation is performed on the content of the file, triggering an RCE vulnerability by uploading a web shell. Further the name parameter is not sanitized, allowing the payload to be uploaded to any directory to which the server has write access. | |||||
CVE-2022-42971 | 2 Microsoft, Schneider-electric | 8 Windows 10, Windows 11, Windows 7 and 5 more | 2023-02-08 | N/A | 9.8 CRITICAL |
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GA), APC Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GA-01-22261), Schneider Electric Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022 - Versions prior to V2.5-GS), Schneider Electric Easy UPS Online Monitoring Software (Windows 11, Windows Server 2019, 2022 - Versions prior to V2.5-GS-01-22261) | |||||
CVE-2020-10963 | 1 Frozennode | 1 Laravel-administrator | 2023-02-03 | 6.5 MEDIUM | 7.2 HIGH |
FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued. | |||||
CVE-2019-4292 | 1 Ibm | 1 Security Guardium | 2023-02-03 | 6.5 MEDIUM | 8.8 HIGH |
IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable web server. IBM X-Force ID: 160698. | |||||
CVE-2020-10934 | 1 Acyba | 1 Acymailing | 2023-02-03 | 6.5 MEDIUM | 7.2 HIGH |
Acyba AcyMailing before 6.9.2 mishandles file uploads by admins. |