CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2021-42123 HIGH
Businessdnasolutions Topease < 7.1.27 - Unrestricted File Upload
CVSS 7.3
CVE-2021-44094 HIGH
Zrlog - Unrestricted File Upload
CVSS 7.8
CVE-2021-44093 CRITICAL
Zrlog - Unrestricted File Upload
CVSS 9.8
CVE-2021-22968 HIGH
Concrete CMS <8.5.6 - RCE
CVSS 7.2
CVE-2021-42362 HIGH
Wordpress Popular Posts < 5.3.2 - Unrestricted File Upload
CVSS 8.8
CVE-2021-39222 MEDIUM
Nextcloud Talk < 10.0.7 - XSS
CVSS 6.4
CVE-2021-42839 HIGH
Vice Webopac - Unrestricted File Upload
CVSS 8.8
CVE-2021-43617 CRITICAL
Laravel Framework <8.70.2 - Code Injection
CVSS 9.8
CVE-2021-3915 MEDIUM
Bookstack < 21.10.3 - Unrestricted File Upload
CVSS 5.7
CVE-2021-41833 CRITICAL
Zohocorp Manageengine Patch Connect Plus - Unrestricted File Upload
CVSS 9.8
CVE-2021-28023 CRITICAL
ServiceTonic Helpdesk < 9.0.35937 - Code Injection
CVSS 9.8
CVE-2021-34685 LOW
Hitachi Vantara Pentaho < 9.1.0.0 - Unrestricted File Upload
CVSS 2.7
CVE-2021-31599 HIGH
Hitachi Vantara Pentaho < 9.1.0.0 - Unrestricted File Upload
CVSS 8.8
CVE-2021-42669 CRITICAL
Engineers Online Portal - Unrestricted File Upload
CVSS 9.8
CVE-2021-26740 CRITICAL
Doyocms - Unrestricted File Upload
CVSS 9.8
CVE-2021-38847 HIGH
S-Cart <6.4.1 - Code Injection
CVSS 8.8
CVE-2021-41646 CRITICAL
Online Reviewer System - Unrestricted File Upload
CVSS 9.8
CVE-2021-41645 HIGH
Oretnom23 Budget And Expense Tracker System - Unrestricted File Upload
CVSS 8.8
CVE-2021-41644 CRITICAL
Online Food Ordering System - Unrestricted File Upload
CVSS 9.8
CVE-2021-41643 CRITICAL
Church Management System - Unrestricted File Upload
CVSS 9.8
CVE-2021-41675 HIGH
E-negosyo System - Unrestricted File Upload
CVSS 7.2
CVE-2021-36548 CRITICAL
Monstra v3.0.4 - RCE
CVSS 9.8
CVE-2021-36547 CRITICAL
Mara 7.5 - RCE
CVSS 9.8
CVE-2021-3745 MEDIUM
flatcore-cms - Unrestricted Upload of File with Dangerous Type
CVSS 6.6
CVE-2021-3906 MEDIUM
Bookstack < 21.10.1 - Unrestricted File Upload
CVSS 6.5
Details
Vulnerabilities 4,018
Exploit Likelihood Medium