Vulnerabilities (CVE)

Filtered by CWE-434
Total 2367 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3125 1 Najeebmedia 1 Frontend File Manager 2022-10-04 N/A 8.8 HIGH
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE
CVE-2022-40886 1 Dedecms 1 Dedecms 2022-10-04 N/A 7.2 HIGH
DedeCMS 5.7.98 has a file upload vulnerability in the background.
CVE-2022-41437 1 Billing System Project Project 1 Billing System Project 2022-10-04 N/A 7.2 HIGH
Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php.
CVE-2022-40407 1 Chamilo 1 Chamilo 2022-10-04 N/A 8.8 HIGH
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
CVE-2020-4588 2 Ibm, Microsoft 2 I2 Ibase, Windows 2022-09-30 6.8 MEDIUM 7.8 HIGH
IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579.
CVE-2021-45790 1 Metersphere 1 Metersphere 2022-09-30 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.
CVE-2022-37346 1 Ec-cube 1 Product Image Bulk Upload 2022-09-30 N/A 9.8 CRITICAL
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system.
CVE-2022-40878 1 Exam Reviewer Management System Project 1 Exam Reviewer Management System 2022-09-28 N/A 8.8 HIGH
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
CVE-2022-40050 1 Zfile 1 Zfile 2022-09-28 N/A 9.8 CRITICAL
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
CVE-2021-24284 1 Kaswara Project 1 Kaswara 2022-09-28 7.5 HIGH 9.8 CRITICAL
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as PHP.
CVE-2022-3076 1 Cminds 1 Cm Download Manager 2022-09-27 N/A 7.2 HIGH
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
CVE-2022-3257 1 Mattermost 1 Mattermost Server 2022-09-26 N/A 6.5 MEDIUM
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.
CVE-2022-40087 1 Simple College Website Project 1 Simple College Website 2022-09-26 N/A 9.8 CRITICAL
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-2872 1 Octoprint 1 Octoprint 2022-09-23 N/A 5.4 MEDIUM
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-40217 1 Xplodedthemes 1 Wpide 2022-09-23 N/A 7.2 HIGH
Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-36386 1 Soflyy 1 Wp All Import 2022-09-23 N/A 7.2 HIGH
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
CVE-2022-38916 1 Pagekit 1 Pagekit 2022-09-21 N/A 9.8 CRITICAL
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
CVE-2022-38887 1 D8s-python Project 1 D8s-python 2022-09-21 N/A 9.8 CRITICAL
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.
CVE-2022-40431 1 D8s-pdfs Project 1 D8s-pdfs 2022-09-21 N/A 9.8 CRITICAL
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
CVE-2022-40432 1 D8s-strings Project 1 D8s-strings 2022-09-21 N/A 9.8 CRITICAL
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.