CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-0537 HIGH
MapPress Maps for WordPress <2.73.13 - Auth Bypass
CVSS 7.2
CVE-2022-0403 HIGH
Library File Manager <5.2.3 - CSRF
CVSS 8.1
CVE-2022-28062 HIGH
Online Car Rental System - Unrestricted File Upload
CVSS 8.8
CVE-2022-27435 HIGH
Ecommerce-website - Unrestricted File Upload
CVSS 8.8
CVE-2022-27249 HIGH
Idearespa Reftree < 2021.09.17 - Unrestricted File Upload
CVSS 8.8
CVE-2022-23155 HIGH
Dell Wyse Management Suite < 3.5.2 - Unrestricted File Upload
CVSS 7.2
CVE-2022-24136 CRITICAL
Hospital Management System v1.0 - Code Injection
CVSS 9.8
CVE-2022-26645 CRITICAL
Online Banking System Protect v1.0 - RCE
CVSS 9.8
CVE-2022-28223 CRITICAL
Tekon Kio Firmware < 2022-03-30 - Unrestricted File Upload
CVSS 9.1
CVE-2022-0499 HIGH
Sermon Browser WP <0.45.22 - CSRF
CVSS 8.8
CVE-2022-23880 CRITICAL
taoCMS <3.0.2 - Code Injection
CVSS 9.8
CVE-2022-22952 CRITICAL
Vmware Carbon Black App Control < 8.5.14 - Unrestricted File Upload
CVSS 9.1
CVE-2022-0888 CRITICAL
Ninjaforms Ninja Forms File Uploads < 3.3.0 - Unrestricted File Upload
CVSS 9.8
CVE-2022-1033 HIGH
Crater < 6.0.6 - Unrestricted File Upload
CVSS 7.8
CVE-2022-1034 HIGH
Showdoc < 2.10.4 - Unrestricted File Upload
CVSS 7.2
CVE-2022-23346 HIGH
Bigantsoft Bigant Server - Unrestricted File Upload
CVSS 8.8
CVE-2022-0687 HIGH
Amelia WordPress <1.0.47 - Code Injection
CVSS 8.8
CVE-2022-0415 HIGH
gogs <0.12.6 - RCE
CVSS 8.8
CVE-2022-25581 HIGH
Classcms < 2.5 - Unrestricted File Upload
CVSS 7.8
CVE-2022-25602 HIGH
Expresstech Responsive Menu < 4.1.7 - Information Disclosure
CVSS 8.3
CVE-2022-26965 HIGH
Pluck 4.7.16 - Authenticated RCE
CVSS 7.2
CVE-2022-0959 MEDIUM
Pgadmin 4 < 6.7 - Path Traversal
CVSS 6.5
CVE-2022-25495 CRITICAL
Cuppacms - Unrestricted File Upload
CVSS 9.8
CVE-2022-25487 CRITICAL
Thedigitalcraft Atomcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-0951 MEDIUM
Showdoc < 2.10.3 - XSS
CVSS 6.1
Details
Vulnerabilities 4,018
Exploit Likelihood Medium