Vulnerabilities (CVE)

Filtered by CWE-434
Total 2650 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-46839 1 Wiselyhub 1 Js Help Desk 2024-11-21 N/A 10.0 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.
CVE-2022-46828 2 Apple, Jetbrains 2 Macos, Intellij Idea 2024-11-21 N/A 5.2 MEDIUM
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVE-2022-46660 1 Ge 1 Proficy Historian 2024-11-21 N/A 7.5 HIGH
An unauthorized user could alter or write files with full control over the path and content of the file.
CVE-2022-46610 1 72crm 1 Wukong Crm 2024-11-21 N/A 8.8 HIGH
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-46604 1 Tecrail 1 Responsive Filemanager 2024-11-21 N/A 8.8 HIGH
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution.
CVE-2022-46493 1 Nbnbk Project 1 Nbnbk 2024-11-21 N/A 9.8 CRITICAL
Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.
CVE-2022-46135 1 Aerocms Project 1 Aerocms 2024-11-21 N/A 7.2 HIGH
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.
CVE-2022-46102 1 Ayacms Project 1 Ayacms 2024-11-21 N/A 9.8 CRITICAL
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
CVE-2022-46020 1 Wbce 1 Wbce Cms 2024-11-21 N/A 9.8 CRITICAL
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
CVE-2022-45968 1 Alist Project 1 Alist 2024-11-21 N/A 8.8 HIGH
Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).
CVE-2022-45966 1 Classcms Project 1 Classcms 2024-11-21 N/A 9.8 CRITICAL
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
CVE-2022-45912 1 Zimbra 1 Collaboration 2024-11-21 N/A 7.2 HIGH
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for remote code execution.
CVE-2022-45896 1 Planetestream 1 Planet Estream 2024-11-21 N/A 9.8 CRITICAL
Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.
CVE-2022-45802 1 Apache 1 Streampark 2024-11-21 N/A 9.8 CRITICAL
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade to Apache StreamPark 2.0.0 or later
CVE-2022-45759 1 Sens Project 1 Sens 2024-11-21 N/A 8.8 HIGH
SENS v1.0 has a file upload vulnerability.
CVE-2022-45548 1 Ayacms Project 1 Ayacms 2024-11-21 N/A 8.8 HIGH
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
CVE-2022-45527 1 Institutional Management Website Project 1 Institutional Management Website 2024-11-21 N/A 9.8 CRITICAL
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
CVE-2022-45476 1 Tiny File Manager Project 1 Tiny File Manager 2024-11-21 N/A 9.8 CRITICAL
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.
CVE-2022-45427 1 Dahuasecurity 8 Dhi-dss4004-s2, Dhi-dss4004-s2 Firmware, Dhi-dss7016d-s2 and 5 more 2024-11-21 N/A 7.2 HIGH
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files.
CVE-2022-45377 1 Codedropz 1 Drag And Drop Multiple File Upload For Woocommerce 2024-11-21 N/A 6.5 MEDIUM
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.