CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-41382 CRITICAL
d8s-json <0.1.0 - Code Injection
CVSS 9.8
CVE-2022-41381 CRITICAL
d8s-utility <0.1.0 - Code Injection
CVSS 9.8
CVE-2022-41380 CRITICAL
d8s-yaml 0.1.0 - Code Injection
CVSS 9.8
CVE-2022-42229 HIGH
Wedding Planner - Unrestricted File Upload
CVSS 8.8
CVE-2022-42034 HIGH
Wedding Planner - Unrestricted File Upload
CVSS 8.8
CVE-2022-3436 MEDIUM
Web-based Student Clearance System - Unrestricted File Upload
CVSS 6.3
CVE-2022-41379 HIGH
Online Leave Management System v1.0 - RCE
CVSS 7.2
CVE-2022-42092 HIGH
Backdropcms Backdrop Cms - Unrestricted File Upload
CVSS 7.2
CVE-2022-41512 HIGH
Online Diagnostic Lab Management System <1.0 - RCE
CVSS 7.2
CVE-2022-40721 CRITICAL
Creativedream File Uploader - Unrestricted File Upload
CVSS 9.8
CVE-2022-3125 HIGH
Najeebmedia Frontend File Manager < 21.3 - Unrestricted File Upload
CVSS 8.8
CVE-2022-40886 HIGH
DedeCMS 5.7.98 - File Upload Vulnerability
CVSS 7.2
CVE-2022-40341 HIGH
Mojoportal - Unrestricted File Upload
CVSS 8.8
CVE-2022-41437 HIGH
Billing System Project v1.0 - RCE
CVSS 7.2
CVE-2022-36066 CRITICAL
Discourse <2.8.9-2.9.0.beta10 - RCE
CVSS 9.1
CVE-2022-40407 HIGH
Chamilo - Unrestricted File Upload
CVSS 8.8
CVE-2022-40048 HIGH
Flatpress - Unrestricted File Upload
CVSS 7.2
CVE-2022-40878 HIGH
Exam Reviewer Management System 1.0 - Authenticated RCE
CVSS 8.8
CVE-2022-37346 CRITICAL
Ec-cube Product Image Bulk Upload - Unrestricted File Upload
CVSS 9.8
CVE-2022-40050 CRITICAL
Zfile - Unrestricted File Upload
CVSS 9.8
CVE-2022-40925 HIGH
Zoo Management System v1.0 - File Upload
CVSS 7.2
CVE-2022-40924 HIGH
Zoo Management System v1.0 - File Upload
CVSS 7.2
CVE-2022-3076 HIGH
CM Download Manager <2.8.6 - Privilege Escalation
CVSS 7.2
CVE-2022-3257 LOW
Mattermost <7.1 - DoS
CVSS 3.1
CVE-2022-40087 CRITICAL
Simple College Website - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium