Vulnerabilities (CVE)

Filtered by CWE-434
Total 2765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36582 1 Garage Management System Project 1 Garage Management System 2022-09-02 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-36580 1 Online Ordering System Project 1 Online Ordering System 2022-09-02 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-36557 1 Seiko-sol 4 Skybridge Mb-a100, Skybridge Mb-a100 Firmware, Skybridge Mb-a110 and 1 more 2022-09-02 N/A 9.8 CRITICAL
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.
CVE-2020-29450 1 Atlassian 2 Confluence Data Center, Confluence Server 2022-08-30 4.0 MEDIUM 6.5 MEDIUM
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.
CVE-2022-37181 1 72crm 1 Wukong Crm 2022-08-29 N/A 9.8 CRITICAL
72crm 9.0 has an Arbitrary file upload vulnerability.
CVE-2022-37159 1 Claroline 1 Claroline 2022-08-27 N/A 9.8 CRITICAL
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
CVE-2022-36285 1 Uploading Svg\, Webp And Ico Files Project 1 Uploading Svg\, Webp And Ico Files 2022-08-26 N/A 7.2 HIGH
Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
CVE-2021-29891 1 Ibm 8 Hardware Management Console 7063-cr2, Hardware Management Console 7063-cr2 Firmware, Power System Ac922 \(8335-gtg\) and 5 more 2022-08-25 N/A 4.9 MEDIUM
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
CVE-2022-2594 1 Advancedcustomfields 1 Advanced Custom Fields 2022-08-23 N/A 8.8 HIGH
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release.
CVE-2022-35150 1 Baijiacms Project 1 Baijiacms 2022-08-23 N/A 9.8 CRITICAL
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-2180 1 Greyd 1 Greyd.suite 2022-08-16 N/A 9.8 CRITICAL
The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).
CVE-2022-2779 1 Gas Agency Management System Project 1 Gas Agency Management System 2022-08-16 N/A 9.8 CRITICAL
A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulnerability is an unknown functionality of the file /gasmark/assets/myimages/oneWord.php. The manipulation of the argument shell leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206173 was assigned to this vulnerability.
CVE-2022-2744 1 Gym Management System Project 1 Gym Management System 2022-08-15 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality of the file /admin/add_exercises.php of the component Background Management. The manipulation of the argument exer_img leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206012.
CVE-2022-2749 1 Gym Management System Project 1 Gym Management System 2022-08-15 N/A 8.8 HIGH
A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/index.php?view_exercises. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206017 was assigned to this vulnerability.
CVE-2022-2746 1 Simple Online Book Store System Project 1 Simple Online Book Store System 2022-08-15 N/A 9.8 CRITICAL
A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code of the file Admin_ add.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-206014 is the identifier assigned to this vulnerability.
CVE-2022-2736 1 Company Website Cms Project 1 Company Website Cms 2022-08-15 N/A 9.8 CRITICAL
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-205881 was assigned to this vulnerability.
CVE-2022-2740 1 Company Website Cms Project 1 Company Website Cms 2022-08-15 N/A 9.8 CRITICAL
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882 is the identifier assigned to this vulnerability.
CVE-2022-2750 1 Company Website Cms Project 1 Company Website Cms 2022-08-15 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the identifier assigned to this vulnerability.
CVE-2022-2751 1 Company Website Cms Project 1 Company Website Cms 2022-08-15 N/A 9.8 CRITICAL
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206024.
CVE-2022-35426 1 Ucms Project 1 Ucms 2022-08-12 N/A 9.8 CRITICAL
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.