Vulnerabilities (CVE)

Filtered by CWE-434
Total 2650 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-43838 1 Personal-management-system 1 Personal Management System 2024-11-21 N/A 7.8 HIGH
An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
CVE-2023-43740 1 Projectworlds 1 Online Book Store Project 2024-11-21 N/A 8.8 HIGH
Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
CVE-2023-43696 1 Sick 2 Apu0200, Apu0200 Firmware 2024-11-21 N/A 8.2 HIGH
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
CVE-2023-43619 1 Schollz 1 Croc 2024-11-21 N/A 7.8 HIGH
An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized_keys file.
CVE-2023-43497 1 Jenkins 1 Jenkins 2024-11-21 N/A 8.1 HIGH
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.
CVE-2023-43478 1 Telstra 2 Arcadyan Lh1000, Arcadyan Lh1000 Firmware 2024-11-21 N/A 8.8 HIGH
fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root. 
CVE-2023-43321 1 Dcnetworks 2 Dcfw-1800-sdc, Dcfw-1800-sdc Firmware 2024-11-21 N/A 8.8 HIGH
File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.
CVE-2023-43269 1 Pigcms 1 Pigcms 2024-11-21 N/A 9.8 CRITICAL
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.
CVE-2023-43226 1 Dedecms 1 Dedecms 2024-11-21 N/A 8.8 HIGH
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2023-42803 1 Bigbluebutton 1 Bigbluebutton 2024-11-21 N/A 5.3 MEDIUM
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton 2.6.0-beta.2 contains a patch. There are no known workarounds.
CVE-2023-42802 1 Glpi-project 1 Glpi 2024-11-21 N/A 10.0 CRITICAL
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system libraries, malicious PHP files can then be executed through a web server request. Version 10.0.10 fixes this issue. As a workaround, remove write access on `/ajax` and `/front` files to the web server.
CVE-2023-42659 1 Progress 1 Ws Ftp Server 2024-11-21 N/A 9.1 CRITICAL
In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system hosting the WS_FTP Server application.
CVE-2023-42472 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 N/A 8.7 HIGH
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an authenticated attacker could intercept the request, modify the content type and the extension to read and modify sensitive data causing a high impact on confidentiality and integrity of the application.
CVE-2023-42462 1 Glpi-project 1 Glpi 2024-11-21 N/A 7.7 HIGH
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. The document upload process can be diverted to delete some files. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability.
CVE-2023-42335 1 Fl3xx 2 Crew, Dispatch 2024-11-21 N/A 8.8 HIGH
Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.
CVE-2023-42331 1 Elitecms 1 Elite Cms 2024-11-21 N/A 8.8 HIGH
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.
CVE-2023-42286 2024-11-21 N/A N/A
There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.
CVE-2023-42180 1 Lenosp Project 1 Lenosp 2024-11-21 N/A 8.8 HIGH
An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file.
CVE-2023-42017 1 Ibm 1 Planning Analytics 2024-11-21 N/A 8.0 HIGH
IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious script, which could allow the attacker to execute arbitrary code on the vulnerable system. IBM X-Force ID: 265567.
CVE-2023-41998 1 Arcserve 1 Udp 2024-11-21 N/A 9.8 CRITICAL
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.