Skip to content
Threat Feed

Tag

Unrestricted-Upload

7 briefs RSS
high advisory

CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability

A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.

DNS-320 1.0.2 web-vulnerability remote-code-execution file-upload d-link unrestricted-file-upload nas vulnerability unrestricted-upload +2
4r 4t 2i updated
high advisory

CVE-2026-16324: Metasoft MetaCRM Unrestricted File Upload Vulnerability

A high-severity vulnerability, CVE-2026-16324, exists in Metasoft MetaCRM up to version 6.4.0 Beta06, allowing remote attackers to perform unrestricted file uploads by manipulating the 'File' argument within the `/business/qnaire/upload.jsp` component, which can lead to webshell deployment and remote code execution; a public exploit is available, increasing the risk of attack.

MetaCRM cve rce unrestricted-upload web-vulnerability metasystem
1r 2t 1c
high advisory

Remote SQL Injection in code-projects Online Job Portal (CVE-2026-15675)

A SQL injection vulnerability (CVE-2026-15675) has been identified in code-projects Online Job Portal version 1.0, located in the `/Admin/EditUser.php` file and triggered by manipulating the `UserId` argument, allowing for remote SQL injection attacks with publicly available exploit code.

Online Job Portal 1.0 sql-injection web-application cve vulnerability rce unrestricted-upload
2r 5t 1c
high threat

Metasoft MetaCRM Unrestricted File Upload Vulnerability (CVE-2026-8758)

A vulnerability in Metasoft MetaCRM up to version 6.4.0 Beta06 allows for unrestricted file upload due to manipulation of the 'File' argument in the /common/jsp/upload3.jsp file, potentially leading to arbitrary code execution.

exploited MetaCRM unrestricted-upload rce web-application
2r 1t 1c
high advisory

Langflow Unrestricted File Upload Vulnerability (CVE-2026-6596)

An unrestricted file upload vulnerability in langflow-ai langflow versions up to 1.1.0 allows remote attackers to execute arbitrary code via the create_upload_file function in the API Endpoint.

CVE-2026-6596 unrestricted-upload langflow
2r 2t
critical advisory

Shandong Hoteam InforCenter PLM Unrestricted Upload Vulnerability (CVE-2026-5261)

CVE-2026-5261 is an unrestricted file upload vulnerability in Shandong Hoteam InforCenter PLM up to version 8.3.8, allowing remote attackers to execute arbitrary code by uploading malicious files via the uploadFileToIIS function.

CVE-2026-5261 unrestricted-upload hoteam-plm
2r 3t 1c
high advisory

PromtEngineer localGPT Unrestricted Upload Vulnerability (CVE-2026-5001)

A remote attacker can exploit an unrestricted file upload vulnerability (CVE-2026-5001) in PromtEngineer localGPT up to version 4d41c7d1713b16b216d8e062e51a5dd88b20b054 via the do_POST function in backend/server.py.

localGPT unrestricted-upload remote-code-execution
2r 1t