Total
1580 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-45359 | 1 Yithemes | 1 Yith Woocommerce Gift Cards | 2022-12-07 | N/A | 9.8 CRITICAL |
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. | |||||
CVE-2022-45548 | 1 Ayacms Project | 1 Ayacms | 2022-12-07 | N/A | 8.8 HIGH |
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. | |||||
CVE-2020-27386 | 1 Flexdotnetcms Project | 1 Flexdotnetcms | 2022-12-06 | 6.5 MEDIUM | 8.8 HIGH |
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or the FileManager's rename function (in v1.5.7 and prior) to rename the file to an executable extension (e.g., ASP), and finally executing the file via an HTTP GET request to /<path_to_file>. | |||||
CVE-2022-1540 | 1 Postmagthemes | 1 Postmagthemes Demo Import | 2022-12-06 | N/A | 7.2 HIGH |
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE. | |||||
CVE-2022-4272 | 1 Warehouse Management System Project | 1 Warehouse Management System | 2022-12-06 | N/A | 9.8 CRITICAL |
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214760. | |||||
CVE-2022-4273 | 1 Human Resource Management System Project | 1 Human Resource Management System | 2022-12-05 | N/A | 9.8 CRITICAL |
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument pfimg leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214769 was assigned to this vulnerability. | |||||
CVE-2022-4276 | 1 House Rental System Project | 1 House Rental System | 2022-12-05 | N/A | 9.8 CRITICAL |
A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214772. | |||||
CVE-2022-36431 | 1 Rocketsoftware | 1 Trufusion | 2022-12-05 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1. | |||||
CVE-2020-25042 | 1 Maracms | 1 Maracms | 2022-12-03 | 6.5 MEDIUM | 7.2 HIGH |
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php. | |||||
CVE-2022-4232 | 1 Event Registration System Project | 1 Event Registration System | 2022-12-01 | N/A | 9.8 CRITICAL |
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the attack remotely. VDB-214590 is the identifier assigned to this vulnerability. | |||||
CVE-2022-38140 | 1 Squirrly | 1 Seo Plugin By Squirrly Seo | 2022-12-01 | N/A | 8.8 HIGH |
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress. | |||||
CVE-2022-44354 | 1 Contec | 2 Solarview Compact, Solarview Compact Firmware | 2022-12-01 | N/A | 9.8 CRITICAL |
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. | |||||
CVE-2022-30529 | 1 Isic.lk Project | 1 Isic.lk | 2022-11-30 | N/A | 7.2 HIGH |
File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/upload.php. | |||||
CVE-2022-41705 | 1 Uatech | 1 Badaso | 2022-11-30 | N/A | 9.8 CRITICAL |
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users. | |||||
CVE-2021-43258 | 1 Churchdb | 1 Churchinfo | 2022-11-30 | N/A | 8.8 HIGH |
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server. | |||||
CVE-2020-5844 | 1 Artica | 1 Pandora Fms | 2022-11-29 | 6.5 MEDIUM | 7.2 HIGH |
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020. | |||||
CVE-2022-45039 | 1 Wbce | 1 Wbce Cms | 2022-11-28 | N/A | 7.2 HIGH |
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-44401 | 1 Online Tours \& Travels Management System Project | 1 Online Tours \& Travels Management System | 2022-11-28 | N/A | 9.8 CRITICAL |
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php. | |||||
CVE-2022-44400 | 1 Purchase Order Management System Project | 1 Purchase Order Management System | 2022-11-28 | N/A | 9.8 CRITICAL |
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info. | |||||
CVE-2022-2791 | 1 Emerson | 1 Proficy | 2022-11-25 | N/A | 7.8 HIGH |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC. |