Total
2367 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-41626 | 1 Gradio Project | 1 Gradio | 2023-09-19 | N/A | 4.8 MEDIUM |
Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface. | |||||
CVE-2023-40731 | 1 Siemens | 1 Qms Automotive | 2023-09-14 | N/A | 8.8 HIGH |
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could potentially lead to code tampering. | |||||
CVE-2023-2071 | 1 Rockwellautomation | 2 Factorytalk View, Panelview Plus | 2023-09-14 | N/A | 9.8 CRITICAL |
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to execute exported functions from libraries. There is a routine that restricts it to execute specific functions from two dynamic link library files. By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function. | |||||
CVE-2023-40784 | 1 Dedecms | 1 Dedecms | 2023-09-14 | N/A | 9.8 CRITICAL |
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. | |||||
CVE-2021-42967 | 1 Xxyopen | 1 Novel-plus | 2023-09-13 | 7.5 HIGH | 9.8 CRITICAL |
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files. | |||||
CVE-2021-41921 | 1 Xxyopen | 1 Novel-plus | 2023-09-13 | 7.5 HIGH | 9.8 CRITICAL |
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | |||||
CVE-2023-41564 | 1 Agentejo | 1 Cockpit | 2023-09-13 | N/A | 6.1 MEDIUM |
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file. | |||||
CVE-2023-42472 | 1 Sap | 1 Businessobjects Business Intelligence Platform | 2023-09-13 | N/A | 7.3 HIGH |
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an authenticated attacker could intercept the request, modify the content type and the extension to read and modify sensitive data causing a high impact on confidentiality and integrity of the application. | |||||
CVE-2023-39424 | 1 Resortdata | 1 Internet Reservation Module Next Generation | 2023-09-12 | N/A | 8.8 HIGH |
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials. | |||||
CVE-2023-41108 | 1 Tef | 1 Tef Portal | 2023-09-11 | N/A | 8.8 HIGH |
TEF portal 2023-07-17 is vulnerable to authenticated remote code execution. | |||||
CVE-2023-41009 | 1 Adlered | 1 Bolo-solo | 2023-09-08 | N/A | 9.8 CRITICAL |
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header. | |||||
CVE-2023-40980 | 1 Diaowen | 1 Dwsurvey | 2023-09-07 | N/A | 9.8 CRITICAL |
File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. | |||||
CVE-2023-41637 | 1 Grupposcai | 1 Realgimm | 2023-09-06 | N/A | 9.8 CRITICAL |
An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file. | |||||
CVE-2023-41638 | 1 Grupposcai | 1 Realgimm | 2023-09-05 | N/A | 8.8 HIGH |
An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file. | |||||
CVE-2020-18912 | 1 Earcms | 1 Ear | 2023-08-31 | N/A | 9.8 CRITICAL |
An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php. | |||||
CVE-2023-40825 | 1 Perfree | 1 Perfreeblog | 2023-08-30 | N/A | 7.2 HIGH |
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list. | |||||
CVE-2023-38029 | 1 Saho | 4 Adm-100, Adm-100 Firmware, Adm-100fp and 1 more | 2023-08-29 | N/A | 9.8 CRITICAL |
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service. | |||||
CVE-2023-32757 | 1 Edetw | 1 U-office Force | 2023-08-29 | N/A | 9.8 CRITICAL |
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service. | |||||
CVE-2023-39970 | 1 Acyba | 1 Acymailing Starter | 2023-08-23 | N/A | 9.8 CRITICAL |
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution. | |||||
CVE-2023-35808 | 1 Sugarcrm | 1 Sugarcrm | 2023-08-23 | N/A | 8.8 HIGH |
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be injected and executed through the Notes module because of missing input validation. Regular user privileges can be used to exploit this vulnerability. Editions other than Enterprise are also affected. |