Filtered by CWE-434
Total 3401 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-10994 1 Codezips 1 Online Institute Management System 2024-11-18 6.3 Medium
A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit_user.php. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-52408 1 Pushassist 1 Push Notifications 2024-11-18 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Team PushAssist Push Notifications for WordPress by PushAssist allows Upload a Web Shell to a Web Server.This issue affects Push Notifications for WordPress by PushAssist: from n/a through 3.0.8.
CVE-2024-52403 1 Wpexperts 1 User Management 2024-11-18 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in WPExperts User Management allows Upload a Web Shell to a Web Server.This issue affects User Management: from n/a through 1.1.
CVE-2024-52404 1 Bigfive 1 Contact Form 7 2024-11-18 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Bigfive CF7 Reply Manager.This issue affects CF7 Reply Manager: from n/a through 1.2.3.
CVE-2024-52380 1 Softpulse Infotech 1 Picsmize 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Softpulse Infotech Picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from n/a through 1.0.0.
CVE-2024-52384 1 Sageai 1 Sage Ai 2024-11-15 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Sage AI Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation allows Upload a Web Shell to a Web Server.This issue affects Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation: from n/a through 2.4.9.
CVE-2024-52379 1 Kinetic Innovative Technologies Sdn Bhd 1 Kineticpay For Woocommerce 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Kinetic Innovative Technologies Sdn Bhd kineticPay for WooCommerce allows Upload a Web Shell to a Web Server.This issue affects kineticPay for WooCommerce: from n/a through 2.0.8.
CVE-2024-52377 1 Bdthemes 1 Instant Image Generator 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in BdThemes Instant Image Generator allows Upload a Web Shell to a Web Server.This issue affects Instant Image Generator: from n/a through 1.5.4.
CVE-2024-52376 1 Cmsminds 1 Boat Rental Plugin For Wordpress 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in cmsMinds Boat Rental Plugin for WordPress allows Upload a Web Shell to a Web Server.This issue affects Boat Rental Plugin for WordPress: from n/a through 1.0.1.
CVE-2024-52375 1 Arttia Creative 1 Datasets Manager 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative.This issue affects Datasets Manager by Arttia Creative: from n/a through 1.5.
CVE-2024-52374 1 Dothattask 1 Do That Task 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task allows Upload a Web Shell to a Web Server.This issue affects Do That Task: from n/a through 1.5.5.
CVE-2024-52373 1 Team Devexhub 1 Devexhub Gallery 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery allows Upload a Web Shell to a Web Server.This issue affects Devexhub Gallery: from n/a through 2.0.1.
CVE-2024-52370 1 Hivesupport 1 Hive Support 2024-11-15 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support – WordPress Help Desk allows Upload a Web Shell to a Web Server.This issue affects Hive Support – WordPress Help Desk: from n/a through 1.1.1.
CVE-2024-52369 1 Optimal Access 1 Kbucket 2024-11-15 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access Inc. KBucket allows Upload a Web Shell to a Web Server.This issue affects KBucket: from n/a through 4.1.6.
CVE-2024-52372 1 Webtechglobal 1 Easy Csv Importer Beta 2024-11-15 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA allows Upload a Web Shell to a Web Server.This issue affects Easy CSV Importer BETA: from n/a through 7.0.0.
CVE-2024-52302 2024-11-15 N/A
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).
CVE-2024-51793 1 Webfulcreations 1 Computer Repair Shop 2024-11-14 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in Webful Creations Computer Repair Shop allows Upload a Web Shell to a Web Server.This issue affects Computer Repair Shop: from n/a through 3.8115.
CVE-2024-37179 1 Sap 1 Businessobjects Business Intelligence 2024-11-14 7.7 High
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.
CVE-2024-11054 2 Oretnom23, Sourcecodester 2 Simple Music Cloud Community System, Simple Music Cloud Community System 2024-11-14 6.3 Medium
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-51152 1 Alexstack 1 Laravel Cms 2024-11-13 7.2 High
File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.