Total
2650 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-46839 | 1 Wiselyhub | 1 Js Help Desk | 2024-11-21 | N/A | 10.0 CRITICAL |
Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1. | |||||
CVE-2022-46828 | 2 Apple, Jetbrains | 2 Macos, Intellij Idea | 2024-11-21 | N/A | 5.2 MEDIUM |
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible. | |||||
CVE-2022-46660 | 1 Ge | 1 Proficy Historian | 2024-11-21 | N/A | 7.5 HIGH |
An unauthorized user could alter or write files with full control over the path and content of the file. | |||||
CVE-2022-46610 | 1 72crm | 1 Wukong Crm | 2024-11-21 | N/A | 8.8 HIGH |
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |||||
CVE-2022-46604 | 1 Tecrail | 1 Responsive Filemanager | 2024-11-21 | N/A | 8.8 HIGH |
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution. | |||||
CVE-2022-46493 | 1 Nbnbk Project | 1 Nbnbk | 2024-11-21 | N/A | 9.8 CRITICAL |
Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img. | |||||
CVE-2022-46135 | 1 Aerocms Project | 1 Aerocms | 2024-11-21 | N/A | 7.2 HIGH |
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server. | |||||
CVE-2022-46102 | 1 Ayacms Project | 1 Ayacms | 2024-11-21 | N/A | 9.8 CRITICAL |
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php | |||||
CVE-2022-46020 | 1 Wbce | 1 Wbce Cms | 2024-11-21 | N/A | 9.8 CRITICAL |
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | |||||
CVE-2022-45968 | 1 Alist Project | 1 Alist | 2024-11-21 | N/A | 8.8 HIGH |
Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one). | |||||
CVE-2022-45966 | 1 Classcms Project | 1 Classcms | 2024-11-21 | N/A | 9.8 CRITICAL |
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. | |||||
CVE-2022-45912 | 1 Zimbra | 1 Collaboration | 2024-11-21 | N/A | 7.2 HIGH |
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for remote code execution. | |||||
CVE-2022-45896 | 1 Planetestream | 1 Planet Estream | 2024-11-21 | N/A | 9.8 CRITICAL |
Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution. | |||||
CVE-2022-45802 | 1 Apache | 1 Streampark | 2024-11-21 | N/A | 9.8 CRITICAL |
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later | |||||
CVE-2022-45759 | 1 Sens Project | 1 Sens | 2024-11-21 | N/A | 8.8 HIGH |
SENS v1.0 has a file upload vulnerability. | |||||
CVE-2022-45548 | 1 Ayacms Project | 1 Ayacms | 2024-11-21 | N/A | 8.8 HIGH |
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. | |||||
CVE-2022-45527 | 1 Institutional Management Website Project | 1 Institutional Management Website | 2024-11-21 | N/A | 9.8 CRITICAL |
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory. | |||||
CVE-2022-45476 | 1 Tiny File Manager Project | 1 Tiny File Manager | 2024-11-21 | N/A | 9.8 CRITICAL |
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload. | |||||
CVE-2022-45427 | 1 Dahuasecurity | 8 Dhi-dss4004-s2, Dhi-dss4004-s2 Firmware, Dhi-dss7016d-s2 and 5 more | 2024-11-21 | N/A | 7.2 HIGH |
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files. | |||||
CVE-2022-45377 | 1 Codedropz | 1 Drag And Drop Multiple File Upload For Woocommerce | 2024-11-21 | N/A | 6.5 MEDIUM |
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8. |