Vulnerabilities (CVE)

Filtered by CWE-434
Total 2642 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41902 1 Corecode 1 Macupdater 2024-02-28 N/A 7.8 HIGH
An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files.
CVE-2023-42335 1 Fl3xx 2 Crew, Dispatch 2024-02-28 N/A 8.8 HIGH
Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.
CVE-2023-2071 1 Rockwellautomation 2 Factorytalk View, Panelview Plus 2024-02-28 N/A 9.8 CRITICAL
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.
CVE-2023-34207 1 Easyuse 1 Mailhunter Ultimate 2024-02-28 N/A 8.8 HIGH
Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate 2023 and earlier allows remote authenticated users to perform arbitrary system commands with ‘NT Authority\SYSTEM‘ privilege via a crafted ZIP archive.
CVE-2023-41108 1 Tef 1 Tef Portal 2024-02-28 N/A 8.8 HIGH
TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.
CVE-2023-43740 1 Projectworlds 1 Online Book Store Project 2024-02-28 N/A 8.8 HIGH
Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
CVE-2023-44973 1 Emlog 1 Emlog 2024-02-28 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2023-46004 1 Mayurik 1 Best Courier Management System 2024-02-28 N/A 7.2 HIGH
Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.
CVE-2023-41637 1 Grupposcai 1 Realgimm 2024-02-28 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.
CVE-2023-42331 1 Elitecms 1 Elite Cms 2024-02-28 N/A 8.8 HIGH
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.
CVE-2023-35018 1 Ibm 1 Security Verify Governance 2024-02-28 N/A 7.2 HIGH
IBM Security Verify Governance 10.0 could allow a privileged use to upload arbitrary files due to improper file validation. IBM X-Force ID: 259382.
CVE-2023-32757 1 Edetw 1 U-office Force 2024-02-28 N/A 9.8 CRITICAL
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
CVE-2023-38029 1 Saho 4 Adm-100, Adm-100 Firmware, Adm-100fp and 1 more 2024-02-28 N/A 9.8 CRITICAL
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service.
CVE-2023-40731 1 Siemens 1 Qms Automotive 2024-02-28 N/A 8.8 HIGH
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to upload arbitrary file types. This could allow an attacker to upload malicious files, that could potentially lead to code tampering.
CVE-2023-5601 1 Atomicwebstrategy 1 Woocommerce Ninja Forms Product Add-ons 2024-02-28 N/A 9.8 CRITICAL
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
CVE-2023-42802 1 Glpi-project 1 Glpi 2024-02-28 N/A 9.8 CRITICAL
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on `/ajax` and `/front` files to the web server.
CVE-2023-28482 1 Tigergraph 1 Tigergraph 2024-02-28 N/A 6.5 MEDIUM
An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).
CVE-2023-38836 1 Boidcms 1 Boidcms 2024-02-28 N/A 8.8 HIGH
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
CVE-2023-28480 1 Tigergraph 1 Tigergraph 2024-02-28 N/A 6.5 MEDIUM
An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload custom C/C++ code which is then compiled and installed into the platform. An attacker who has filesystem access on a remote TigerGraph system can alter the behavior of the database against the will of the database administrator; thus effectively bypassing the built in RBAC controls.
CVE-2023-31946 1 Online Travel Agency System Project 1 Online Travel Agency System 2024-02-28 N/A 7.2 HIGH
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.