CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-31854 HIGH
Codologic Codoforum - Unrestricted File Upload
CVSS 7.2
CVE-2022-32413 CRITICAL
Dice - Unrestricted File Upload
CVSS 9.8
CVE-2022-2268 HIGH
Soflyy WP All Import < 3.6.8 - Unrestricted File Upload
CVSS 7.2
CVE-2022-31943 CRITICAL
Mingsoft Mcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-32994 CRITICAL
Halo CMS <1.5.3 - File Upload
CVSS 9.8
CVE-2022-31086 HIGH
LDAP Account Manager <8.0 - RCE
CVSS 8.8
CVE-2022-2212 MEDIUM
Library Management System - Unrestricted File Upload
CVSS 6.3
CVE-2022-2102 CRITICAL
PHP - Code Injection
CVSS 9.4
CVE-2022-1519 CRITICAL
Illumina Local Run Manager < 3.1 - Unrestricted File Upload
CVSS 10.0
CVE-2022-31362 HIGH
Docebo Community Edition <4.0.5 - Arbitrary File Upload
CVSS 8.8
CVE-2022-31374 CRITICAL
SolarView Compact 6.0 - RCE
CVSS 9.8
CVE-2022-2128 CRITICAL
GitHub polonel/trudesk <1.2.4 - File Injection
CVSS 9.8
CVE-2022-1939 HIGH
WordPress Plugin <1.1 - Code Injection
CVSS 7.2
CVE-2022-2111 HIGH
Inventree < 0.7.2 - Unrestricted File Upload
CVSS 8.8
CVE-2022-32433 HIGH
Advanced School Management System - Unrestricted File Upload
CVSS 7.2
CVE-2022-31041 HIGH
Open Forms <1.0.9, 1.1.1 - File Upload Bypass
CVSS 7.6
CVE-2022-0863 HIGH
WP Svg Icons < 3.2.3 - Unrestricted File Upload
CVSS 7.2
CVE-2022-30860 HIGH
FUDforum 3.1.2 - RCE
CVSS 7.2
CVE-2022-32019 CRITICAL
Car Rental Management System - Unrestricted File Upload
CVSS 9.8
CVE-2022-30822 HIGH
Wedding Management System v1.0 - File Upload
CVSS 8.8
CVE-2022-30821 HIGH
Wedding Management System v1.0 - File Upload
CVSS 8.8
CVE-2022-30820 HIGH
Wedding Management v1.0 - File Upload
CVSS 8.8
CVE-2022-30819 HIGH
Wedding Management System v1.0 - File Upload
CVSS 8.8
CVE-2022-30808 CRITICAL
elitecms 1.0.1 - Code Injection
CVSS 9.8
CVE-2022-30506 CRITICAL
Mingsoft Mcms - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium