Show filters
1,378 Total Results
Displaying 141-150 of 1,378
Sort by:
Attacker Value
Unknown

CVE-2023-3491

Disclosure Date: June 30, 2023 (last updated February 25, 2025)
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
Attacker Value
Unknown

CVE-2023-32621

Disclosure Date: June 30, 2023 (last updated February 25, 2025)
WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands with the root privilege.
Attacker Value
Unknown

CVE-2020-18432

Disclosure Date: June 30, 2023 (last updated February 25, 2025)
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
Attacker Value
Unknown

CVE-2023-34738

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
Chemex through 3.7.1 is vulnerable to arbitrary file upload.
Attacker Value
Unknown

CVE-2023-34736

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
Attacker Value
Unknown

CVE-2022-44276

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
Attacker Value
Unknown

CVE-2023-32526

Disclosure Date: June 26, 2023 (last updated February 25, 2025)
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32525.
Attacker Value
Unknown

CVE-2023-32525

Disclosure Date: June 26, 2023 (last updated February 25, 2025)
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32526.
Attacker Value
Unknown

CVE-2023-33404

Disclosure Date: June 26, 2023 (last updated February 25, 2025)
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
Attacker Value
Unknown

CVE-2020-20210

Disclosure Date: June 26, 2023 (last updated February 25, 2025)
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.