CWE-434
Medium likelihoodUnrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
4,018 vulnerabilities with CWE-434
CVE-2022-29655
HIGH
Wedding Management System - Unrestricted File Upload
CVSS 7.2
CVE-2022-29318
HIGH
Car Rental Management System 1.0 - RCE
CVSS 7.2
CVE-2022-28606
CRITICAL
BossCMS 1.0 - RCE
CVSS 9.8
CVE-2022-28120
CRITICAL
Rainier Open Virtual Simulation Exper... - Unrestricted File Upload
CVSS 9.8
CVE-2022-1411
MEDIUM
Yetiforce Customer Relationship Management - Unrestricted File Upload
CVSS 6.1
CVE-2022-29347
CRITICAL
Web@rchiv 1.0 - Code Injection
CVSS 9.8
CVE-2022-28568
CRITICAL
Sourcecodester Doctor's Appointment System 1.0 - RCE
CVSS 9.8
CVE-2022-29001
HIGH
SpringBootMovie <=1.2 - File Upload
CVSS 7.2
CVE-2022-20743
MEDIUM
Cisco Firepower Management Center - Auth Bypass
CVSS 6.5
CVE-2022-1273
HIGH
Importwp Import WP < 2.4.6 - Unrestricted File Upload
CVSS 7.2
CVE-2022-29451
HIGH
Rarathemes Rara One Click Demo Import < 1.3.0 - CSRF
CVSS 8.8
CVE-2022-28528
HIGH
bloofoxCMS <0.5.2.1 - File Upload
CVSS 8.8
CVE-2022-28525
HIGH
ED01-CMS v20180505 - File Upload
CVSS 8.8
CVE-2022-27468
CRITICAL
Monstaftp Monsta FTP - Unrestricted File Upload
CVSS 9.8
CVE-2022-22392
HIGH
IBM Planning Analytics Local 2.0 - Code Injection
CVSS 7.8
CVE-2022-28053
HIGH
Typemill - Unrestricted File Upload
CVSS 8.8
CVE-2022-28440
HIGH
UCMS <1.6 - RCE
CVSS 8.8
CVE-2022-28021
CRITICAL
Purchase Order Management System - Unrestricted File Upload
CVSS 9.8
CVE-2022-27478
HIGH
Victor Cms - Unrestricted File Upload
CVSS 8.8
CVE-2022-27862
CRITICAL
Vikwp Vikbooking Hotel Booking Engine... - Unrestricted File Upload
CVSS 9.8
CVE-2022-1329
HIGH
Elementor Website Builder < 3.6.2 - Missing Authorization
CVSS 8.8
CVE-2022-1345
CRITICAL
Organizr < 2.1.1810 - Unrestricted File Upload
CVSS 9.0
CVE-2022-28397
CRITICAL
Ghost CMS <4.42.0 - RCE
CVSS 9.8
CVE-2022-27952
CRITICAL
Payload < 0.15.1 - Unrestricted File Upload
CVSS 9.8
CVE-2022-27263
CRITICAL
Strapi - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities
4,018
Exploit Likelihood
Medium