CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2021-38841 HIGH
Simple Water Refilling Station Management System 1.0 - RCE
CVSS 8.8
CVE-2021-40531 CRITICAL
Sketch <75 - RCE
CVSS 9.8
CVE-2021-40524 HIGH
Pure-FTPd <1.0.50 - DoS
CVSS 7.5
CVE-2021-36042 CRITICAL
Magento Commerce <2.4.2-2.3.7 - RCE
CVSS 9.1
CVE-2021-36040 CRITICAL
Magento Commerce <2.4.2-2.3.7 - RCE
CVSS 9.1
CVE-2021-29907 HIGH
IBM Openpages With Watson < 8.1.0.2.1 - Unrestricted File Upload
CVSS 8.8
CVE-2021-36356 CRITICAL
KRAMER VIAware - RCE
CVSS 9.8
CVE-2021-32955 CRITICAL
Delta Electronics DIAEnergie <1.7.5 - RCE
CVSS 9.8
CVE-2021-40175 CRITICAL
Zoho ManageEngine Log360 <Build 5219 - RCE
CVSS 9.8
CVE-2021-33884 MEDIUM
Bbraun Spacecom2 < 012u000062 - Unrestricted File Upload
CVSS 6.5
CVE-2021-38613 CRITICAL
NASCENT RemKon Device Mgr <4.0.0.0 - RCE
CVSS 9.8
CVE-2021-39608 HIGH
Flatcore-cms - Unrestricted File Upload
CVSS 7.2
CVE-2021-39154 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39153 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39151 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39149 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39148 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39147 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39146 HIGH
Debian Linux < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39145 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39141 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-39139 HIGH
Xstream < 1.4.18 - Insecure Deserialization
CVSS 8.5
CVE-2021-37608 CRITICAL
Apache Ofbiz < 17.12.08 - Unrestricted File Upload
CVSS 9.8
CVE-2021-22937 HIGH
Pulse Connect Secure <9.1R12 - Privilege Escalation
CVSS 7.2
CVE-2021-38753 CRITICAL
Simple Image Gallery Web App - Code Injection
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium