CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-30423 CRITICAL
Merchandise Online Store - Unrestricted File Upload
CVSS 9.8
CVE-2022-29725 HIGH
Creatiwity Witycms - Unrestricted File Upload
CVSS 8.8
CVE-2022-29624 HIGH
Tpcms - Unrestricted File Upload
CVSS 8.8
CVE-2022-24581 HIGH
ACEweb Online Portal 3.5.065 - Info Disclosure
CVSS 7.5
CVE-2022-24239 CRITICAL
ACEweb Online Portal <3.5.065 - Unrestricted File Upload
CVSS 9.8
CVE-2022-29637 HIGH
Iminho Mindoc - Unrestricted File Upload
CVSS 7.8
CVE-2022-29632 CRITICAL
Roncoo-education - Unrestricted File Upload
CVSS 9.8
CVE-2022-29651 HIGH
Online Food Ordering System - Unrestricted File Upload
CVSS 7.2
CVE-2022-1837 MEDIUM
Home Clean Services Management System - Unrestricted File Upload
CVSS 4.7
CVE-2022-1811 MEDIUM
Publify < 9.2.9 - Unrestricted File Upload
CVSS 5.4
CVE-2022-1752 HIGH
Trudesk < 1.2.2 - Unrestricted File Upload
CVSS 8.0
CVE-2022-30887 CRITICAL
Pharmacy Management System v1.0 - RCE
CVSS 9.8
CVE-2022-28104 CRITICAL
Foxit Pdf Editor - Unrestricted File Upload
CVSS 9.8
CVE-2022-28927 CRITICAL
Subconverter 0.7.2 - RCE
CVSS 9.8
CVE-2022-22482 MEDIUM
IBM Sterling B2B Integrator Standard Edition <6.0.3.5, <6.1.1.0 - DoS
CVSS 6.5
CVE-2022-30007 HIGH
Gxcms - Unrestricted File Upload
CVSS 7.2
CVE-2022-1409 HIGH
Vikwp Hotel Booking Engine & Pms < 1.5.8 - Unrestricted File Upload
CVSS 7.2
CVE-2022-1103 HIGH
Advanced Uploader < 4.2 - Unrestricted File Upload
CVSS 8.8
CVE-2022-29623 HIGH
Connect-multiparty - Unrestricted File Upload
CVSS 7.8
CVE-2022-29622 CRITICAL
Formidable < 3.2.4 - Unrestricted File Upload
CVSS 9.8
CVE-2022-29354 CRITICAL
Keystone v4.2.1 - Code Injection
CVSS 9.8
CVE-2022-29353 CRITICAL
Graphql-upload <13.0.0 - Code Injection
CVSS 9.8
CVE-2022-29351 CRITICAL
Tiddlywiki5 <5.2.2 - RCE
CVSS 9.8
CVE-2022-21809 HIGH
InHand Networks InRouter302 V3.5.4 - File Write
CVSS 8.1
CVE-2022-30448 CRITICAL
Hospital Management System - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium