Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-434
Total 1580 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45359 1 Yithemes 1 Yith Woocommerce Gift Cards 2022-12-07 N/A 9.8 CRITICAL
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
CVE-2022-45548 1 Ayacms Project 1 Ayacms 2022-12-07 N/A 8.8 HIGH
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
CVE-2020-27386 1 Flexdotnetcms Project 1 Flexdotnetcms 2022-12-06 6.5 MEDIUM 8.8 HIGH
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or the FileManager's rename function (in v1.5.7 and prior) to rename the file to an executable extension (e.g., ASP), and finally executing the file via an HTTP GET request to /<path_to_file>.
CVE-2022-1540 1 Postmagthemes 1 Postmagthemes Demo Import 2022-12-06 N/A 7.2 HIGH
The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) leading to RCE.
CVE-2022-4272 1 Warehouse Management System Project 1 Warehouse Management System 2022-12-06 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown functionality of the file /product/savenewproduct.php?flag=1. The manipulation of the argument upfile leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214760.
CVE-2022-4273 1 Human Resource Management System Project 1 Human Resource Management System 2022-12-05 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument pfimg leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-214769 was assigned to this vulnerability.
CVE-2022-4276 1 House Rental System Project 1 House Rental System 2022-12-05 N/A 9.8 CRITICAL
A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214772.
CVE-2022-36431 1 Rocketsoftware 1 Trufusion 2022-12-05 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
CVE-2020-25042 1 Maracms 1 Maracms 2022-12-03 6.5 MEDIUM 7.2 HIGH
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authenticated (admin/manager) session and make a codebase/dir.php?type=filenew request to upload PHP code to codebase/handler.php.
CVE-2022-4232 1 Event Registration System Project 1 Event Registration System 2022-12-01 N/A 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the attack remotely. VDB-214590 is the identifier assigned to this vulnerability.
CVE-2022-38140 1 Squirrly 1 Seo Plugin By Squirrly Seo 2022-12-01 N/A 8.8 HIGH
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
CVE-2022-44354 1 Contec 2 Solarview Compact, Solarview Compact Firmware 2022-12-01 N/A 9.8 CRITICAL
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
CVE-2022-30529 1 Isic.lk Project 1 Isic.lk 2022-11-30 N/A 7.2 HIGH
File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/upload.php.
CVE-2022-41705 1 Uatech 1 Badaso 2022-11-30 N/A 9.8 CRITICAL
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.
CVE-2021-43258 1 Churchdb 1 Churchinfo 2022-11-30 N/A 8.8 HIGH
CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment for the email stores the attachment on the site in the /tmp_attach/ folder where it can be accessed with a GET request. There are no limitations on files that can be attached, allowing for malicious PHP code to be uploaded and interpreted by the server.
CVE-2020-5844 1 Artica 1 Pandora Fms 2022-11-29 6.5 MEDIUM 7.2 HIGH
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the file location. This affects v7.0NG.742_FIX_PERL2020.
CVE-2022-45039 1 Wbce 1 Wbce Cms 2022-11-28 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-44401 1 Online Tours \& Travels Management System Project 1 Online Tours \& Travels Management System 2022-11-28 N/A 9.8 CRITICAL
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
CVE-2022-44400 1 Purchase Order Management System Project 1 Purchase Order Management System 2022-11-28 N/A 9.8 CRITICAL
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
CVE-2022-2791 1 Emerson 1 Proficy 2022-11-25 N/A 7.8 HIGH
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.