CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-34154 HIGH
WordPress ideasToCode <1.0.1 - RCE
CVSS 7.2
CVE-2022-34496 CRITICAL
Hiby R3 Pro Firmware < 1.7 - Unrestricted File Upload
CVSS 9.8
CVE-2022-34578 HIGH
Opensourcepos Open Source Point OF Sale - Unrestricted File Upload
CVSS 7.2
CVE-2022-34120 HIGH
Barangay Management System v1.0 - RCE
CVSS 7.2
CVE-2022-34549 HIGH
Sims - Unrestricted File Upload
CVSS 8.8
CVE-2022-34971 HIGH
Feehi Cms - Unrestricted File Upload
CVSS 8.8
CVE-2022-34965 HIGH
Openteknik Open Source Social Network - Unrestricted File Upload
CVSS 7.2
CVE-2022-34115 CRITICAL
DataEase v1.11.1 - File Write
CVSS 9.8
CVE-2022-28700 CRITICAL
GiveWP <2.20.2 - Code Injection
CVSS 9.1
CVE-2022-34024 HIGH
Barangay Management System v1.0 - File Upload
CVSS 7.2
CVE-2022-1565 HIGH
Wpallimport WP All Import < 3.6.8 - Unrestricted File Upload
CVSS 7.2
CVE-2022-24688 HIGH
DSK DSKNet <2.17.136.5 - RCE
CVSS 8.8
CVE-2022-31161 CRITICAL
Roxy-WI <6.1.1.0 - Command Injection
CVSS 10.0
CVE-2022-32119 HIGH
Arox School Erp Pro - Unrestricted File Upload
CVSS 8.8
CVE-2022-2420 HIGH
Eveo Urve Web Manager - Unrestricted File Upload
CVSS 8.0
CVE-2022-2419 HIGH
Eveo Urve Web Manager - Unrestricted File Upload
CVSS 8.0
CVE-2022-2418 HIGH
Eveo Urve Web Manager - Unrestricted File Upload
CVSS 8.0
CVE-2022-22450 LOW
IBM Security Verify Identity Manager 10.0 - Privilege Escalation
CVSS 3.8
CVE-2022-28372 HIGH
Verizon 5G Home LVSKIHP IDU/ODU - File Upload
CVSS 7.5
CVE-2022-28369 CRITICAL
Verizon 5G Home LVSKIHP InDoorUnit IDU 3.4.66.162 - RCE
CVSS 9.8
CVE-2022-32114 HIGH
Strapi - Unrestricted File Upload
CVSS 8.8
CVE-2022-30216 HIGH
Microsoft Windows 10 - Unrestricted File Upload
CVSS 8.8
CVE-2022-31134 MEDIUM
Zulip Server >2.1.0 - Info Disclosure
CVSS 4.9
CVE-2022-2297 MEDIUM
Oretnom23 Clinic's Patient Management... - Unrestricted File Upload
CVSS 6.3
CVE-2022-1952 CRITICAL
Free Booking Plugin <1.1.16 - RCE
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium