Vulnerabilities (CVE)

Filtered by CWE-434
Total 4402 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36066 1 Discourse 1 Discourse 2026-06-17 N/A 9.1 CRITICAL
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and trigger remote code execution. The problem is patched in version 2.8.9 on the `stable` branch and version 2.9.0.beta10 on the `beta` and `tests-passed` branches. There are no known workarounds.
CVE-2022-35426 1 Ucms Project 1 Ucms 2026-06-17 N/A 9.8 CRITICAL
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
CVE-2022-35150 1 Baijiacms Project 1 Baijiacms 2026-06-17 N/A 9.8 CRITICAL
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-34971 1 Feehi 1 Feehi Cms 2026-06-17 N/A 8.8 HIGH
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-34965 1 Openteknik 1 Open Source Social Network 2026-06-17 N/A 7.2 HIGH
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior of the application as it only allows authenticated admins to upload files.
CVE-2022-34613 1 Mealie Project 1 Mealie 2026-06-17 N/A 9.8 CRITICAL
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.
CVE-2022-34578 1 Opensourcepos 1 Open Source Point Of Sale 2026-06-17 N/A 7.2 HIGH
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
CVE-2022-34549 1 Sims Project 1 Sims 2026-06-17 N/A 8.8 HIGH
Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulnerability allows attackers to escalate privileges and execute arbitrary commands via a crafted file.
CVE-2022-34496 1 Hiby 4 Hiby R3 Pro, Hiby R3 Pro Firmware, Hiby R3 Pro Saber and 1 more 2026-06-17 N/A 9.8 CRITICAL
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
CVE-2022-34483 1 Mozilla 1 Firefox 2026-06-17 N/A 8.8 HIGH
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34482. This vulnerability affects Firefox < 102.
CVE-2022-34482 1 Mozilla 1 Firefox 2026-06-17 N/A 8.8 HIGH
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34483. This vulnerability affects Firefox < 102.
CVE-2022-34154 1 Ideastocode 1 Enable Svg\, Webp \& Ico Upload 2026-06-17 N/A 7.2 HIGH
Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
CVE-2022-34128 1 Glpi-project 1 Positions 2026-06-17 N/A 9.8 CRITICAL
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
CVE-2022-34120 1 Barangay Management System Project 1 Barangay Management System 2026-06-17 N/A 7.2 HIGH
Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php.
CVE-2022-34115 1 Dataease 1 Dataease 2026-06-17 N/A 9.8 CRITICAL
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
CVE-2022-34024 1 Barangay Management System Project 1 Barangay Management System 2026-06-17 N/A 7.2 HIGH
Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.
CVE-2022-33859 1 Eaton 1 Foreseer Electrical Power Monitoring System 2026-06-17 N/A 8.1 HIGH
A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast array of devices to assist in the reduction of energy consumption and avoid unplanned downtime caused by the failures of critical systems. A threat actor may upload arbitrary files using the file upload feature. This vulnerability is present in versions 4.x, 5.x, 6.x & 7.0 to 7.5. A new version (v7.6) containing the remediation has been made available by Eaton and a mitigation has been provided for the affected versions that are currently supported. Customers are advised to update the software to the latest version (v7.6). Foreseer EPMS versions 4.x, 5.x, 6.x are no longer supported by Eaton. Please refer to the End-of-Support notification https://www.eaton.com/in/en-us/catalog/services/foreseer/foreseer-legacy.html .
CVE-2022-33166 1 Ibm 1 Security Directory Suite Va 2026-06-17 N/A 7.2 HIGH
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586.
CVE-2022-32994 1 Halo 1 Halo 2026-06-17 7.5 HIGH 9.8 CRITICAL
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
CVE-2022-32433 1 Advanced School Management System Project 1 Advanced School Management System 2026-06-17 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to Arbitrary code execution via ip/school/view/all_teacher.php.