Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-434
Total 1580 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1034 1 Showdoc 1 Showdoc 2022-03-28 6.5 MEDIUM 7.2 HIGH
There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-1033 1 Craterapp 1 Crater 2022-03-28 6.5 MEDIUM 7.8 HIGH
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
CVE-2020-26008 1 Shopxo 1 Shopxo 2022-03-28 6.8 MEDIUM 7.8 HIGH
The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2020-26007 1 Shopxo 1 Shopxo 2022-03-28 6.8 MEDIUM 7.8 HIGH
An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2022-25581 1 Classcms 1 Classcms 2022-03-28 6.8 MEDIUM 7.8 HIGH
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.
CVE-2022-0959 1 Postgresql 1 Pgadmin 4 2022-03-28 3.5 LOW 6.5 MEDIUM
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under which pgAdmin is running has permission to write.
CVE-2019-18288 1 Siemens 1 Sppa-t3000 Application Server 2022-03-25 6.5 MEDIUM 8.8 HIGH
A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with valid authentication at the RMI interface could be able to gain remote code execution through an unsecured file upload. Please note that an attacker needs to have access to the Application Highway in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.
CVE-2022-25602 1 Expresstech 1 Responsive Menu 2022-03-25 6.5 MEDIUM 8.8 HIGH
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).
CVE-2022-0415 1 Gogs 1 Gogs 2022-03-25 6.5 MEDIUM 8.8 HIGH
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
CVE-2022-26965 1 Pluck-cms 1 Pluck 2022-03-25 6.5 MEDIUM 7.2 HIGH
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
CVE-2021-45834 1 Opendocman 1 Opendocman 2022-03-25 7.5 HIGH 9.8 CRITICAL
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
CVE-2021-45835 1 Online Admission System Project 1 Online Admissions System 2022-03-25 7.5 HIGH 9.8 CRITICAL
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.
CVE-2021-45040 1 Spatie 1 Laravel Media Library 2022-03-24 10.0 HIGH 9.8 CRITICAL
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload executable files via the uploads route.
CVE-2022-25495 1 Cuppacms 1 Cuppacms 2022-03-23 7.5 HIGH 9.8 CRITICAL
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.
CVE-2022-24387 1 Smartertools 1 Smartertrack 2022-03-18 6.5 MEDIUM 7.2 HIGH
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
CVE-2022-0912 1 Microweber 1 Microweber 2022-03-18 3.5 LOW 4.8 MEDIUM
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2021-44673 1 Croogo 1 Croogo 2022-03-18 6.5 MEDIUM 8.8 HIGH
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script.
CVE-2022-0921 1 Microweber 1 Microweber 2022-03-18 6.5 MEDIUM 6.7 MEDIUM
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-26521 1 Abantecart 1 Abantecart 2022-03-17 6.5 MEDIUM 7.2 HIGH
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).
CVE-2021-35244 2 Microsoft, Solarwinds 2 Windows, Orion Platform 2022-03-17 8.5 HIGH 7.2 HIGH
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.