Vulnerabilities (CVE)

Filtered by CWE-434
Total 4403 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45427 1 Dahuasecurity 8 Dhi-dss4004-s2, Dhi-dss4004-s2 Firmware, Dhi-dss7016d-s2 and 5 more 2026-06-17 N/A 7.2 HIGH
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of administrators, by sending a specific crafted packet to the vulnerable interface, an attacker can upload arbitrary files.
CVE-2022-45415 1 Mozilla 1 Firefox 2026-06-17 N/A 7.8 HIGH
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.
CVE-2022-45377 1 Codedropz 1 Drag And Drop Multiple File Upload For Woocommerce 2026-06-17 N/A 6.5 MEDIUM
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.
CVE-2022-45359 1 Yithemes 1 Yith Woocommerce Gift Cards 2026-06-17 N/A 9.8 CRITICAL
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
CVE-2022-45338 1 Exactsoftware 1 Exact Synergy 2026-06-17 N/A 7.8 HIGH
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.
CVE-2022-45275 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2026-06-17 N/A 7.2 HIGH
An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-45171 1 Liveboxcloud 1 Vdesk 2026-06-17 N/A 8.8 HIGH
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially dangerous files without restrictions.
CVE-2022-45039 1 Wbce 1 Wbce Cms 2026-06-17 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-45009 1 Online Leave Management System Project 1 Online Leave Management System 2026-06-17 N/A 7.2 HIGH
Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-44760 1 Hcltech 1 Hcl Leap 2026-06-17 N/A 4.6 MEDIUM
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
CVE-2022-44401 1 Online Tours \& Travels Management System Project 1 Online Tours \& Travels Management System 2026-06-17 N/A 9.8 CRITICAL
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
CVE-2022-44400 1 Purchase Order Management System Project 1 Purchase Order Management System 2026-06-17 N/A 9.8 CRITICAL
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
CVE-2022-44384 1 Rconfig 1 Rconfig 2026-06-17 N/A 8.8 HIGH
An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-44354 1 Contec 2 Solarview Compact, Solarview Compact Firmware 2026-06-17 N/A 9.8 CRITICAL
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
CVE-2022-44289 1 Thinkphp 1 Thinkphp 2026-06-17 N/A 8.8 HIGH
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
CVE-2022-44276 1 Tecrail 1 Responsive Filemanager 2026-06-17 N/A 9.8 CRITICAL
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
CVE-2022-44054 1 Democritus 1 D8s-xml 2026-06-17 N/A 9.8 CRITICAL
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.
CVE-2022-44053 1 Democritus 1 D8s-networking 2026-06-17 N/A 9.8 CRITICAL
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0.
CVE-2022-44052 1 Democritus 1 D8s-dates 2026-06-17 N/A 9.8 CRITICAL
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected version of d8s-htm is 0.1.0.
CVE-2022-44051 1 Democritus 1 D8s-stats 2026-06-17 N/A 9.8 CRITICAL
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.