CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-23375 HIGH
Wikidocs - Unrestricted File Upload
CVSS 8.8
CVE-2022-0409 HIGH
Packagist showdoc/showdoc <2.10.2 - File Injection
CVSS 7.8
CVE-2022-24984 CRITICAL
Jqueryform < 2022-02-05 - Unrestricted File Upload
CVSS 9.8
CVE-2022-23390 CRITICAL
Diyhi Bbs Forum < 5.3 - Unrestricted File Upload
CVSS 9.8
CVE-2022-23048 HIGH
Exponentcms Exponent Cms - Unrestricted File Upload
CVSS 7.2
CVE-2022-24676 HIGH
HYBBS2 <2.3.2 - Code Injection
CVSS 8.8
CVE-2022-0472 MEDIUM
Packagist jsdecena/laracom <2.0.9 - File Injection
CVSS 5.4
CVE-2022-23329 CRITICAL
Ujcms Jspxcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-24262 HIGH
Voipmonitor GUI <24.96 - RCE
CVSS 8.8
CVE-2022-23026 MEDIUM
F5 Big-ip Advanced Web Application Firewall - Unrestricted File Upload
CVSS 4.3
CVE-2022-23315 CRITICAL
Mingsoft Mcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-22929 CRITICAL
Mingsoft Mcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-0263 HIGH
Packagist pimcore/pimcore <10.2.7 - File Injection
CVSS 7.8
CVE-2022-0242 HIGH
Crater < 6.0 - Unrestricted File Upload
CVSS 7.2
CVE-2021-35485 HIGH
Nokia IMPACT <=19.11.2.10 - Authenticated RCE
CVSS 8.0
CVE-2021-47904 HIGH
PhreeBooks 5.2.3 - Authenticated RCE
CVSS 8.8
CVE-2021-47899 MEDIUM
YetiShare File Hosting Script 5.1.0 - SSRF
CVSS 4.0
CVE-2021-47888 HIGH
Textpattern <4.8.3 - Authenticated RCE
CVSS 8.8
CVE-2021-47788 HIGH
Websitebaker - Unrestricted File Upload
CVSS 8.8
CVE-2021-47783 MEDIUM
Phpwcms - Unrestricted File Upload
CVSS 5.4
CVE-2021-47819 CRITICAL
ProjeQtOr Project Management 9.1.4 - RCE
CVSS 9.8
CVE-2021-47758 HIGH
Chikitsa Patient Management System - Unrestricted File Upload
CVSS 8.8
CVE-2021-47757 HIGH
Chikitsa Patient Management System - Unrestricted File Upload
CVSS 8.8
CVE-2021-47753 CRITICAL
Phpkf Cms - Unrestricted File Upload
CVSS 9.8
CVE-2021-4462 CRITICAL
Skittles Employee Records System - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium