Vulnerabilities (CVE)

Filtered by CWE-434
Total 1119 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36264 1 Airspan 2 Airspot 5410, Airspot 5410 Firmware 2024-11-21 N/A 9.1 CRITICAL
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious actor can remotely upload a file of their choice and overwrite any file in the system by manipulating the filename and append a relative path that will be interpreted during the upload process. Using this method, it is possible to rewrite any file in the system or upload a new file.
CVE-2022-36066 1 Discourse 1 Discourse 2024-11-21 N/A 9.1 CRITICAL
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and trigger remote code execution. The problem is patched in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.
CVE-2022-35426 1 Ucms Project 1 Ucms 2024-11-21 N/A 9.8 CRITICAL
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
CVE-2022-35150 1 Baijiacms Project 1 Baijiacms 2024-11-21 N/A 9.8 CRITICAL
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-34613 1 Mealie Project 1 Mealie 2024-11-21 N/A 9.8 CRITICAL
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.
CVE-2022-34496 1 Hiby 4 Hiby R3 Pro, Hiby R3 Pro Firmware, Hiby R3 Pro Saber and 1 more 2024-11-21 N/A 9.8 CRITICAL
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
CVE-2022-34115 1 Dataease Project 1 Dataease 2024-11-21 N/A 9.8 CRITICAL
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
CVE-2022-32994 1 Halo 1 Halo 2024-11-21 7.5 HIGH 9.8 CRITICAL
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
CVE-2022-32413 1 Dice Project 1 Dice 2024-11-21 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-32019 1 Car Rental Management System Project 1 Car Rental Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.
CVE-2022-31943 1 Mingsoft 1 Mcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-31374 1 Contec 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware 2024-11-21 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.
CVE-2022-31161 1 Roxy-wi 1 Roxy-wi 2024-11-21 N/A 10.0 CRITICAL
Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.
CVE-2022-30887 1 Pharmacy Management System Project 1 Pharmacy Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CVE-2022-30808 1 Elitecms 1 Elite Cms 2024-11-21 7.5 HIGH 9.8 CRITICAL
elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php.
CVE-2022-30506 1 Mingsoft 1 Mcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
CVE-2022-30448 1 Hospital Management System Project 1 Hospital Management System 2024-11-21 7.5 HIGH 9.8 CRITICAL
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
CVE-2022-30423 1 Merchandise Online Store Project 1 Merchandise Online Store 2024-11-21 7.5 HIGH 9.8 CRITICAL
Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.
CVE-2022-2180 1 Greyd 1 Greyd.suite 2024-11-21 N/A 9.8 CRITICAL
The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).
CVE-2022-2128 1 Trudesk Project 1 Trudesk 2024-11-21 7.5 HIGH 9.8 CRITICAL
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.