CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-29655 HIGH
Wedding Management System - Unrestricted File Upload
CVSS 7.2
CVE-2022-29318 HIGH
Car Rental Management System 1.0 - RCE
CVSS 7.2
CVE-2022-28606 CRITICAL
BossCMS 1.0 - RCE
CVSS 9.8
CVE-2022-28120 CRITICAL
Rainier Open Virtual Simulation Exper... - Unrestricted File Upload
CVSS 9.8
CVE-2022-1411 MEDIUM
Yetiforce Customer Relationship Management - Unrestricted File Upload
CVSS 6.1
CVE-2022-29347 CRITICAL
Web@rchiv 1.0 - Code Injection
CVSS 9.8
CVE-2022-28568 CRITICAL
Sourcecodester Doctor's Appointment System 1.0 - RCE
CVSS 9.8
CVE-2022-29001 HIGH
SpringBootMovie <=1.2 - File Upload
CVSS 7.2
CVE-2022-20743 MEDIUM
Cisco Firepower Management Center - Auth Bypass
CVSS 6.5
CVE-2022-1273 HIGH
Importwp Import WP < 2.4.6 - Unrestricted File Upload
CVSS 7.2
CVE-2022-29451 HIGH
Rarathemes Rara One Click Demo Import < 1.3.0 - CSRF
CVSS 8.8
CVE-2022-28528 HIGH
bloofoxCMS <0.5.2.1 - File Upload
CVSS 8.8
CVE-2022-28525 HIGH
ED01-CMS v20180505 - File Upload
CVSS 8.8
CVE-2022-27468 CRITICAL
Monstaftp Monsta FTP - Unrestricted File Upload
CVSS 9.8
CVE-2022-22392 HIGH
IBM Planning Analytics Local 2.0 - Code Injection
CVSS 7.8
CVE-2022-28053 HIGH
Typemill - Unrestricted File Upload
CVSS 8.8
CVE-2022-28440 HIGH
UCMS <1.6 - RCE
CVSS 8.8
CVE-2022-28021 CRITICAL
Purchase Order Management System - Unrestricted File Upload
CVSS 9.8
CVE-2022-27478 HIGH
Victor Cms - Unrestricted File Upload
CVSS 8.8
CVE-2022-27862 CRITICAL
Vikwp Vikbooking Hotel Booking Engine... - Unrestricted File Upload
CVSS 9.8
CVE-2022-1329 HIGH
Elementor Website Builder < 3.6.2 - Missing Authorization
CVSS 8.8
CVE-2022-1345 CRITICAL
Organizr < 2.1.1810 - Unrestricted File Upload
CVSS 9.0
CVE-2022-28397 CRITICAL
Ghost CMS <4.42.0 - RCE
CVSS 9.8
CVE-2022-27952 CRITICAL
Payload < 0.15.1 - Unrestricted File Upload
CVSS 9.8
CVE-2022-27263 CRITICAL
Strapi - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium