CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-27262 CRITICAL
Sailsjs Skipper - Unrestricted File Upload
CVSS 9.8
CVE-2022-27261 HIGH
Express-fileupload - Unrestricted File Upload
CVSS 7.5
CVE-2022-27260 CRITICAL
Buttercms - Unrestricted File Upload
CVSS 9.8
CVE-2022-27140 CRITICAL
Express-fileupload - Unrestricted File Upload
CVSS 9.8
CVE-2022-27139 CRITICAL
Ghost - Unrestricted File Upload
CVSS 9.8
CVE-2022-24837 MEDIUM
Hedgedoc < 1.9.3 - Information Disclosure
CVSS 5.3
CVE-2022-27115 CRITICAL
Std42 Elfinder < 2.1.61 - Unrestricted File Upload
CVSS 9.8
CVE-2022-1008 HIGH
Ocdi One Click Demo Import < 3.1.0 - Unrestricted File Upload
CVSS 7.2
CVE-2022-1045 MEDIUM
Trudesk < 1.2.0 - Unrestricted File Upload
CVSS 5.4
CVE-2022-27477 CRITICAL
Newbee-mall - Unrestricted File Upload
CVSS 9.8
CVE-2022-27131 CRITICAL
Zbzcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-27129 CRITICAL
Zbzcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-27047 CRITICAL
Moguit Mogu Blog Cms - Unrestricted File Upload
CVSS 9.8
CVE-2022-27357 CRITICAL
Ecommerce-website - Unrestricted File Upload
CVSS 9.8
CVE-2022-27352 HIGH
Simple House Rental System - Unrestricted File Upload
CVSS 8.8
CVE-2022-27351 CRITICAL
Phpgurukul Zoo Management System - Unrestricted File Upload
CVSS 9.8
CVE-2022-27349 HIGH
Socialcodia Social Codia Sms - Unrestricted File Upload
CVSS 7.2
CVE-2022-27346 HIGH
Ecommerce-website - Unrestricted File Upload
CVSS 8.8
CVE-2022-27064 HIGH
Musical World - Unrestricted File Upload
CVSS 8.8
CVE-2022-27061 HIGH
Aerocms - Unrestricted File Upload
CVSS 7.2
CVE-2022-26627 HIGH
Online Project Time Management System v1.0 - RCE
CVSS 8.8
CVE-2022-26607 HIGH
baigo CMS <3.0-alpha-2 - RCE
CVSS 7.2
CVE-2022-26605 HIGH
eZiosuite v2.0.7 - Authenticated File Upload
CVSS 8.8
CVE-2022-26630 HIGH
Jellycms <3.8.1 - File Upload
CVSS 8.8
CVE-2022-26619 HIGH
Halo Blog CMS <1.4.17 - File Upload
CVSS 7.5
Details
Vulnerabilities 4,018
Exploit Likelihood Medium