Total
2765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-36582 | 1 Garage Management System Project | 1 Garage Management System | 2022-09-02 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-36580 | 1 Online Ordering System Project | 1 Online Ordering System | 2022-09-02 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-36557 | 1 Seiko-sol | 4 Skybridge Mb-a100, Skybridge Mb-a100 Firmware, Skybridge Mb-a110 and 1 more | 2022-09-02 | N/A | 9.8 CRITICAL |
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file. | |||||
CVE-2020-29450 | 1 Atlassian | 2 Confluence Data Center, Confluence Server | 2022-08-30 | 4.0 MEDIUM | 6.5 MEDIUM |
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0. | |||||
CVE-2022-37181 | 1 72crm | 1 Wukong Crm | 2022-08-29 | N/A | 9.8 CRITICAL |
72crm 9.0 has an Arbitrary file upload vulnerability. | |||||
CVE-2022-37159 | 1 Claroline | 1 Claroline | 2022-08-27 | N/A | 9.8 CRITICAL |
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. | |||||
CVE-2022-36285 | 1 Uploading Svg\, Webp And Ico Files Project | 1 Uploading Svg\, Webp And Ico Files | 2022-08-26 | N/A | 7.2 HIGH |
Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress. | |||||
CVE-2021-29891 | 1 Ibm | 8 Hardware Management Console 7063-cr2, Hardware Management Console 7063-cr2 Firmware, Power System Ac922 \(8335-gtg\) and 5 more | 2022-08-25 | N/A | 4.9 MEDIUM |
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221. | |||||
CVE-2022-2594 | 1 Advancedcustomfields | 1 Advanced Custom Fields | 2022-08-23 | N/A | 8.8 HIGH |
The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 allows unauthenticated users to upload files allowed in a default WP configuration (so PHP is not possible) if there is a frontend form available. This vulnerability was introduced in the 5.0 rewrite and did not exist prior to that release. | |||||
CVE-2022-35150 | 1 Baijiacms Project | 1 Baijiacms | 2022-08-23 | N/A | 9.8 CRITICAL |
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. | |||||
CVE-2022-2180 | 1 Greyd | 1 Greyd.suite | 2022-08-16 | N/A | 9.8 CRITICAL |
The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE). | |||||
CVE-2022-2779 | 1 Gas Agency Management System Project | 1 Gas Agency Management System | 2022-08-16 | N/A | 9.8 CRITICAL |
A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulnerability is an unknown functionality of the file /gasmark/assets/myimages/oneWord.php. The manipulation of the argument shell leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206173 was assigned to this vulnerability. | |||||
CVE-2022-2744 | 1 Gym Management System Project | 1 Gym Management System | 2022-08-15 | N/A | 9.8 CRITICAL |
A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality of the file /admin/add_exercises.php of the component Background Management. The manipulation of the argument exer_img leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206012. | |||||
CVE-2022-2749 | 1 Gym Management System Project | 1 Gym Management System | 2022-08-15 | N/A | 8.8 HIGH |
A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/index.php?view_exercises. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206017 was assigned to this vulnerability. | |||||
CVE-2022-2746 | 1 Simple Online Book Store System Project | 1 Simple Online Book Store System | 2022-08-15 | N/A | 9.8 CRITICAL |
A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulnerability affects unknown code of the file Admin_ add.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-206014 is the identifier assigned to this vulnerability. | |||||
CVE-2022-2736 | 1 Company Website Cms Project | 1 Company Website Cms | 2022-08-15 | N/A | 9.8 CRITICAL |
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-205881 was assigned to this vulnerability. | |||||
CVE-2022-2740 | 1 Company Website Cms Project | 1 Company Website Cms | 2022-08-15 | N/A | 9.8 CRITICAL |
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882 is the identifier assigned to this vulnerability. | |||||
CVE-2022-2750 | 1 Company Website Cms Project | 1 Company Website Cms | 2022-08-15 | N/A | 9.8 CRITICAL |
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the identifier assigned to this vulnerability. | |||||
CVE-2022-2751 | 1 Company Website Cms Project | 1 Company Website Cms | 2022-08-15 | N/A | 9.8 CRITICAL |
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206024. | |||||
CVE-2022-35426 | 1 Ucms Project | 1 Ucms | 2022-08-12 | N/A | 9.8 CRITICAL |
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. |