CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,010 vulnerabilities with CWE-434
CVE-2025-69559 CRITICAL
Carmelo Computer Book Store - Unrestricted File Upload
CVSS 9.8
CVE-2025-69565 CRITICAL
Fabian Mobile Shop Management System - Unrestricted File Upload
CVSS 9.8
CVE-2025-13374 CRITICAL
Kalrav AI Agent <2.3.3 - File Upload
CVSS 9.8
CVE-2025-70457 CRITICAL
Remyandrade Modern Image Gallery App - Unrestricted File Upload
CVSS 9.8
CVE-2025-69828 CRITICAL
TMS Management Console <6.3.7.27386.20250818 - RCE
CVSS 10.0
CVE-2025-69312 CRITICAL
Xpro Elementor Addons <1.4.19.1 - RCE
CVSS 9.1
CVE-2025-68986 CRITICAL
zozothemes Miion <= 1.2.7 - RCE
CVSS 9.9
CVE-2025-68910 CRITICAL
blazethemes Blogzee <= 1.0.5 - Code Injection
CVSS 9.9
CVE-2025-68909 CRITICAL
blazethemes Blogistic <1.0.5 - UAFDT
CVSS 9.9
CVE-2025-68001 CRITICAL
garidium g-FFL Checkout <2.1.0 - Unrestricted File Upload
CVSS 10.0
CVE-2025-67968 CRITICAL
InspiryThemes Real Homes CRM <1.0.0 - Unrestricted Upload of File w...
CVSS 9.9
CVE-2025-62056 CRITICAL
blazethemes News Event <1.0.1 - Uplaod of File with Dangerous Type
CVSS 9.9
CVE-2025-62050 CRITICAL
Blogmatic <1.0.4 - Uplaod of File with Dangerous Type
CVSS 9.9
CVE-2025-50002 CRITICAL
Farost Energia energia <1.1.2 - RCE
CVSS 10.0
CVE-2025-10856 HIGH
Teknoera <01102025 - Code Injection
CVSS 8.1
CVE-2025-33015 HIGH
IBM Concert <2.1.0 - Code Injection
CVSS 8.8
CVE-2025-55251 LOW
HCL AION - Unrestricted File Upload
CVSS 3.1
CVE-2025-14632 MEDIUM
Filr - Stored XSS
CVSS 4.4
CVE-2025-14894 CRITICAL
Filemanager < 1.0.0 - Unrestricted File Upload
CVSS 9.8
CVE-2025-12957 HIGH
All-in-One Video Gallery <4.5.7 - RCE
CVSS 8.8
CVE-2025-67079 CRITICAL
Agora-project < 25.10 - Unrestricted File Upload
CVSS 9.8
CVE-2025-67077 HIGH
Agora-project < 25.10 - Unrestricted File Upload
CVSS 8.8
CVE-2025-13062 HIGH
Supreme Modules Lite <2.5.62 - RCE
CVSS 8.8
CVE-2025-37175 HIGH
Mobility Conductor - Privilege Escalation
CVSS 7.2
CVE-2025-62182 MEDIUM
Pega Customer Service Framework <25.1.0 - File Upload
Details
Vulnerabilities 4,010
Exploit Likelihood Medium