Vulnerabilities (CVE)

Filtered by CWE-434
Total 2367 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23329 1 Ujcms 1 Jspxcms 2022-02-09 7.5 HIGH 9.8 CRITICAL
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
CVE-2020-29607 1 Pluck-cms 1 Pluck 2022-02-07 6.5 MEDIUM 7.2 HIGH
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which may result in remote code execution.
CVE-2021-46428 1 Simple Chatbot Application Project 1 Simple Chatbot Application 2022-02-02 7.5 HIGH 9.8 CRITICAL
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
CVE-2021-46097 1 Dolphinphp 1 Dolphinphp 2022-02-02 6.5 MEDIUM 8.8 HIGH
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log
CVE-2021-44123 1 Spip 1 Spip 2022-02-02 6.5 MEDIUM 8.8 HIGH
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.
CVE-2021-46116 1 Jpress 1 Jpress 2022-02-02 6.5 MEDIUM 7.2 HIGH
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.
CVE-2021-46115 1 Jpress 1 Jpress 2022-02-01 6.5 MEDIUM 7.2 HIGH
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.
CVE-2022-23026 1 F5 2 Big-ip Advanced Web Application Firewall, Big-ip Application Acceleration Manager 2022-02-01 4.0 MEDIUM 4.3 MEDIUM
On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2020-7569 1 Schneider-electric 1 Webreports 2022-01-31 6.5 MEDIUM 8.8 HIGH
A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to upload arbitrary files due to incorrect verification of user supplied files and achieve remote code execution.
CVE-2021-22698 1 Schneider-electric 1 Ecostruxure Power Build - Rapsody 2022-01-31 6.8 MEDIUM 7.8 HIGH
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
CVE-2021-22697 1 Schneider-electric 1 Ecostruxure Power Build - Rapsody 2022-01-31 6.8 MEDIUM 7.8 HIGH
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a use-after-free condition which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.
CVE-2021-46033 1 Forestblog Project 1 Forestblog 2022-01-28 7.5 HIGH 9.8 CRITICAL
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
CVE-2021-46113 1 Kea-hotel-erp Project 1 Kea-hotel-erp 2022-01-28 6.5 MEDIUM 8.8 HIGH
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
CVE-2021-41550 1 Leostream 1 Connection Broker 2022-01-27 6.5 MEDIUM 7.2 HIGH
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
CVE-2022-23315 1 Mingsoft 1 Mcms 2022-01-26 7.5 HIGH 9.8 CRITICAL
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
CVE-2022-22929 1 Mingsoft 1 Mcms 2022-01-26 7.5 HIGH 9.8 CRITICAL
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.
CVE-2022-0242 1 Craterapp 1 Crater 2022-01-25 6.0 MEDIUM 7.2 HIGH
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.
CVE-2021-45808 1 Jpress 1 Jpress 2022-01-25 6.5 MEDIUM 8.8 HIGH
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
CVE-2021-44651 1 Zohocorp 2 Log360, Manageengine Cloud Security Plus 2022-01-24 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
CVE-2021-46013 1 Free School Management Software Project 1 Free School Management Software 2022-01-24 7.5 HIGH 9.8 CRITICAL
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.