Vulnerabilities (CVE)

Filtered by CWE-434
Total 2367 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50760 1 Kashipara 1 Online Notice Board System 2024-01-10 N/A 8.8 HIGH
Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
CVE-2023-45724 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 9.8 CRITICAL
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.
CVE-2023-51475 1 Wpmlmsoftware 1 Wp Mlm Unilevel 2024-01-08 N/A 9.8 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in IOSS WP MLM SOFTWARE PLUGIN.This issue affects WP MLM SOFTWARE PLUGIN: from n/a through 4.0.
CVE-2023-51421 1 Soft8soft 1 Verge3d 2024-01-08 N/A 8.8 HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
CVE-2023-51468 1 Boiteasite 1 Download Rencontre - Dating Site 2024-01-05 N/A 9.8 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.
CVE-2023-51473 1 Pixelemu 1 Terraclassifieds 2024-01-05 N/A 9.8 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.This issue affects TerraClassifieds – Simple Classifieds Plugin: from n/a through 2.0.3.
CVE-2023-39539 1 Ami 1 Aptio V 2024-01-05 N/A 7.8 HIGH
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 
CVE-2023-39538 1 Ami 1 Aptio V 2024-01-05 N/A 7.8 HIGH
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 
CVE-2023-51410 1 Wpvibes 1 Wp Mail Log 2024-01-05 N/A 8.8 HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in WPVibes WP Mail Log.This issue affects WP Mail Log: from n/a through 1.1.2.
CVE-2023-51411 1 Dynamiapps 1 Frontend Admin 2024-01-05 N/A 9.8 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3.
CVE-2023-51412 1 Piotnet 1 Piotnet Forms 2024-01-05 N/A 9.8 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.
CVE-2023-51417 1 Jorisvm 1 Jvm Gutenberg Rich Text Icons 2024-01-05 N/A 8.8 HIGH
Unrestricted Upload of File with Dangerous Type vulnerability in Joris van Montfort JVM Gutenberg Rich Text Icons.This issue affects JVM Gutenberg Rich Text Icons: from n/a through 1.2.3.
CVE-2023-51419 1 Bertha 1 Bertha Ai 2024-01-05 N/A 9.8 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and Chrome.This issue affects BERTHA AI. Your AI co-pilot for WordPress and Chrome: from n/a through 1.11.10.7.
CVE-2023-50104 1 Zzcms 1 Zzcms 2024-01-05 N/A 9.8 CRITICAL
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.
CVE-2023-50692 1 Jizhicms 1 Jizhicms 2024-01-04 N/A 8.8 HIGH
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
CVE-2023-50038 1 Textpattern 1 Textpattern 2024-01-04 N/A 8.8 HIGH
There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of server permissions.
CVE-2023-5931 1 Rtcamp 1 Rtmedia 2024-01-04 N/A 8.8 HIGH
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server
CVE-2023-5673 1 Wpvibes 1 Wp Mail Log 2024-01-04 N/A 8.8 HIGH
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.
CVE-2023-52086 1 Startutorial 1 Php Backend For Resumable.js 2024-01-04 N/A 8.1 HIGH
resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)
CVE-2023-51034 1 Totolink 2 Ex1200l, Ex1200l Firmware 2024-01-03 N/A 9.8 CRITICAL
TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.