Total
1580 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-34496 | 1 Hiby | 4 Hiby R3 Pro, Hiby R3 Pro Firmware, Hiby R3 Pro Saber and 1 more | 2022-08-05 | N/A | 9.8 CRITICAL |
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature. | |||||
CVE-2022-34120 | 1 Barangay Management System Project | 1 Barangay Management System | 2022-08-04 | N/A | 7.2 HIGH |
Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php. | |||||
CVE-2022-34578 | 1 Opensourcepos | 1 Open Source Point Of Sale | 2022-08-03 | N/A | 7.2 HIGH |
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. | |||||
CVE-2022-34549 | 1 Sims Project | 1 Sims | 2022-08-03 | N/A | 8.8 HIGH |
Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file. | |||||
CVE-2022-34971 | 1 Feehi | 1 Feehi Cms | 2022-08-02 | N/A | 8.8 HIGH |
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-34965 | 1 Openteknik | 1 Open Source Social Network | 2022-08-01 | N/A | 7.2 HIGH |
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2021-29907 | 3 Ibm, Linux, Microsoft | 3 Openpages With Watson, Linux Kernel, Windows | 2022-08-01 | 6.5 MEDIUM | 8.8 HIGH |
IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force ID: 207633. | |||||
CVE-2021-38945 | 1 Ibm | 1 Cognos Analytics | 2022-07-29 | 7.5 HIGH | 9.8 CRITICAL |
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. | |||||
CVE-2022-27260 | 1 Buttercms | 1 Buttercms | 2022-07-28 | 7.5 HIGH | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file. | |||||
CVE-2022-26352 | 1 Dotcms | 1 Dotcms | 2022-07-25 | 6.8 MEDIUM | 9.8 CRITICAL |
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution. | |||||
CVE-2022-24688 | 1 Dsk | 1 Dsknet | 2022-07-25 | N/A | 8.8 HIGH |
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and consequently Remote Code Execution) via PDF upload with PHP content and a .php extension. The attacker must hijack or obtain privileged user access to the Parameters page in order to exploit this issue. (That can be easily achieved by exploiting the Broken Access Control with further Brute-force attack or SQL Injection.) The uploaded file is stored within the database and copied to the sync web folder if the attacker visits a certain .php?action= page. | |||||
CVE-2022-32114 | 1 Strapi | 1 Strapi | 2022-07-25 | 6.5 MEDIUM | 8.8 HIGH |
An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted file. | |||||
CVE-2022-1345 | 1 Organizr | 1 Organizr | 2022-07-25 | 3.5 LOW | 9.0 CRITICAL |
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse. | |||||
CVE-2022-34024 | 1 Barangay Management System Project | 1 Barangay Management System | 2022-07-24 | N/A | 7.2 HIGH |
Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php. | |||||
CVE-2022-28700 | 1 Givewp | 1 Givewp | 2022-07-24 | N/A | 7.2 HIGH |
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. | |||||
CVE-2022-1565 | 1 Wpallimport | 1 Wp All Import | 2022-07-24 | N/A | 7.2 HIGH |
The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_import_get_gz.php file in versions up to, and including, 3.6.7. This makes it possible for authenticated attackers, with administrator level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible. | |||||
CVE-2022-2419 | 1 Eveo | 1 Urve Web Manager | 2022-07-22 | N/A | 8.0 HIGH |
A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code of the file _internal/collector/upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. | |||||
CVE-2022-2420 | 1 Eveo | 1 Urve Web Manager | 2022-07-22 | N/A | 8.0 HIGH |
A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. | |||||
CVE-2022-2418 | 1 Eveo | 1 Urve Web Manager | 2022-07-22 | N/A | 8.0 HIGH |
A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. | |||||
CVE-2022-32119 | 1 Arox | 1 School Erp Pro | 2022-07-22 | N/A | 8.8 HIGH |
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php. |