Vulnerabilities (CVE)

Filtered by CWE-434
Total 3245 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-43050 1 Online Tours And Travels Management System Project 1 Online Tours And Travels Management System 2025-05-05 N/A 7.2 HIGH
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43085 1 Codeastro 1 Restaurant Pos System 2025-05-05 N/A 7.2 HIGH
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43083 1 Vehicle Booking System Project 1 Vehicle Booking System 2025-05-05 N/A 7.2 HIGH
An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43061 1 Online Tours \& Travels Management System Project 1 Online Tours \& Travels Management System 2025-05-05 N/A 7.2 HIGH
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-27562 2025-05-02 N/A 4.6 MEDIUM
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.
CVE-2025-0520 2025-05-02 N/A N/A
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
CVE-2022-42449 2025-05-02 N/A 4.6 MEDIUM
Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications
CVE-2024-11390 2025-05-02 N/A 5.4 MEDIUM
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.
CVE-2025-25016 2025-05-02 N/A 4.3 MEDIUM
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
CVE-2022-3537 1 Addify 1 Role Based Pricing For Woocommerce 2025-05-01 N/A 8.8 HIGH
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP
CVE-2022-44054 1 Democritus 1 D8s-xml 2025-05-01 N/A 9.8 CRITICAL
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.
CVE-2022-43277 1 Canteen Management System Project 1 Canteen Management System 2025-05-01 N/A 7.2 HIGH
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-40797 1 Roxyfileman 1 Roxy Fileman 2025-05-01 N/A 9.8 CRITICAL
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
CVE-2024-29514 1 Lepton-cms 1 Leptoncms 2025-05-01 N/A 8.8 HIGH
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2024-29515 1 Lepton-cms 1 Leptoncms 2025-05-01 N/A 8.8 HIGH
File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and config.php component.
CVE-2024-33120 1 Roothub 1 Roothub 2025-05-01 N/A 9.8 CRITICAL
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.
CVE-2022-43146 1 Canteen Management System Project 1 Canteen Management System 2025-05-01 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43074 1 Ayacms Project 1 Ayacms 2025-05-01 N/A 9.8 CRITICAL
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-28418 1 Webedition 1 Webedition Cms 2025-04-30 N/A 6.5 MEDIUM
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
CVE-2018-15573 1 Reprisesoftware 1 Reprise License Manager 2025-04-30 9.3 HIGH 8.8 HIGH
An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata parameter and a pathname in the lf parameter. By default, the web interface is on port 5054, and does not require authentication. NOTE: the vendor has stated "We do not consider this a vulnerability.