CWE-616 · 7 kayıt
Incomplete Identification of Uploaded File Variables (PHP)
Bu sınıftaki CVE’ler
7 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-67084İstismar yok | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, whichinvoiceplane · invoiceplane · CWE-616 | Kritik9,9 | — | %0,5 | 15 Oca 2026 |
39İzleyin | CVE-2024-29858İstismar yok | In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.misp-project · misp · CWE-616 | Kritik9,8 | — | %0,4 | 21 Mar 2024 |
39İzleyin | CVE-2024-31601İstismar yok | An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.CWE-616 | Kritik9,8 | — | %0,4 | 26 Nis 2024 |
34İzleyin | CVE-2026-67198İstismar yok | Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcherperspective-dev · perspective · CWE-616 | Yüksek8,7 | — | %0,3 | 4 Ağu 2026 |
21İzleyin | CVE-2025-59402İstismar yok | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL flocksafety · bravo compute box firmware · CWE-616 | Orta5,4 | — | %0,2 | 25 Eyl 2025 |
21İzleyin | CVE-2025-52130İstismar yok | File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller.CWE-616 | Orta5,4 | — | %0,2 | 25 Ağu 2025 |
19İzleyin | CVE-2024-52305İstismar yok | UnoPim Stored XSS : Cookie hijacking through Create User functionwebkul · unopim · CWE-616 | Orta4,8 | — | %0,2 | 13 Kas 2024 |
- CVE-2025-6708439İzleyin
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which
KritikCVSS 9,9İstismar yokEPSS %0invoiceplane · invoiceplane15 Oca 2026
- CVE-2024-2985839İzleyin
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
KritikCVSS 9,8İstismar yokEPSS %0misp-project · misp21 Mar 2024
- CVE-2024-3160139İzleyin
An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.
KritikCVSS 9,8İstismar yokEPSS %026 Nis 2024
- CVE-2026-6719834İzleyin
Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher
YüksekCVSS 8,7İstismar yokEPSS %0perspective-dev · perspective4 Ağu 2026
- CVE-2025-5940221İzleyin
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL
OrtaCVSS 5,4İstismar yokEPSS %0flocksafety · bravo compute box firmware25 Eyl 2025
- CVE-2025-5213021İzleyin
File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller.
OrtaCVSS 5,4İstismar yokEPSS %025 Ağu 2025
- CVE-2024-5230519İzleyin
UnoPim Stored XSS : Cookie hijacking through Create User function
OrtaCVSS 4,8İstismar yokEPSS %0webkul · unopim13 Kas 2024