Vulnerabilities (CVE)

Filtered by CWE-434
Total 4396 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34944 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
CVE-2023-31541 1 Ckeditor 1 Ckeditor 2026-07-09 N/A 9.8 CRITICAL
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.
CVE-2023-30185 1 Crmeb 1 Crmeb 2026-07-09 N/A 9.8 CRITICAL
CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.
CVE-2023-27164 1 Halo 1 Halo 2026-07-09 N/A 4.8 MEDIUM
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
CVE-2023-24317 1 Judging Management System Project 1 Judging Management System 2026-07-09 N/A 8.1 HIGH
Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.
CVE-2023-23328 1 Avantfax 1 Avantfax 2026-07-09 N/A 8.8 HIGH
A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file.
CVE-2022-47769 1 Serinf 1 Fast Checkin 2026-07-09 N/A 9.8 CRITICAL
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.
CVE-2022-40341 1 Mojoportal 1 Mojoportal 2026-07-09 N/A 8.8 HIGH
mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file.
CVE-2022-40048 1 Flatpress 1 Flatpress 2026-07-09 N/A 7.2 HIGH
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
CVE-2022-32119 1 Arox 1 School Erp Pro 2026-07-09 N/A 8.8 HIGH
Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.
CVE-2022-31366 1 Eve-ng 1 Eve-ng 2026-07-09 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
CVE-2022-29351 1 Tiddlywiki 1 Tiddlywiki5 2026-07-09 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.
CVE-2022-29347 1 Web\@rchiv Project 1 Web\@rchiv 2026-07-09 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.
CVE-2022-28568 1 Simple Doctor\'s Appointment System Project 1 Simple Doctor\'s Appointment System 2026-07-09 7.5 HIGH 9.8 CRITICAL
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
CVE-2022-28397 1 Ghost 1 Ghost 2026-07-09 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be uploaded and published by trusted users, this is intentional.
CVE-2022-27262 1 Sailsjs 1 Skipper 2026-07-09 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-27260 1 Buttercms 1 Buttercms 2026-07-09 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.
CVE-2022-26645 1 Oretnom23 1 Banking System 2026-07-09 7.5 HIGH 9.8 CRITICAL
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
CVE-2022-26607 1 Baigo 1 Baigo Cms 2026-07-09 6.5 MEDIUM 7.2 HIGH
A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2022-24581 1 Aceware 1 Aceweb Online Portal 2026-07-09 5.0 MEDIUM 7.5 HIGH
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.