Перейти к содержимому
Noroxi

CWE-616 · 7 записей

Incomplete Identification of Uploaded File Variables (PHP)

CVE этого класса

7 записей

  • CVE-2025-67084
    39Наблюдать

    File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which

    КритическаяCVSS 9,9Эксплойта нетEPSS 0 %

    invoiceplane · invoiceplane15 янв. 2026 г.

  • CVE-2024-29858
    39Наблюдать

    In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    misp-project · misp21 мар. 2024 г.

  • CVE-2024-31601
    39Наблюдать

    An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    26 апр. 2024 г.

  • CVE-2026-67198
    34Наблюдать

    Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    perspective-dev · perspective4 авг. 2026 г.

  • CVE-2025-59402
    21Наблюдать

    Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    flocksafety · bravo compute box firmware25 сент. 2025 г.

  • CVE-2025-52130
    21Наблюдать

    File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    25 авг. 2025 г.

  • CVE-2024-52305
    19Наблюдать

    UnoPim Stored XSS : Cookie hijacking through Create User function

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    webkul · unopim13 нояб. 2024 г.

Все классы уязвимостей