CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2020-18886 HIGH
PHPMyWind <5.6 - RCE
CVSS 7.2
CVE-2020-18879 CRITICAL
Bludit v3.8.1 - RCE
CVSS 9.8
CVE-2020-18704 CRITICAL
Django-Widgy <0.8.4 - RCE
CVSS 9.8
CVE-2020-18462 HIGH
AikCms v2.0.0 - Info Disclosure
CVSS 7.2
CVE-2020-20979 CRITICAL
8cms Ljcms - Unrestricted File Upload
CVSS 9.8
CVE-2020-28165 CRITICAL
Easycorp Zentao < 12.4.2 - Unrestricted File Upload
CVSS 9.8
CVE-2020-21359 CRITICAL
Maccms - Unrestricted File Upload
CVSS 9.8
CVE-2020-21976 HIGH
Newsone Cms - Unrestricted File Upload
CVSS 8.8
CVE-2020-28088 CRITICAL
Jeecg Boot - Unrestricted File Upload
CVSS 9.8
CVE-2020-19303 HIGH
Houdunren Hdcms - Unrestricted File Upload
CVSS 7.8
CVE-2020-19302 CRITICAL
Vaethink - Unrestricted File Upload
CVSS 9.8
CVE-2020-22249 CRITICAL
Phplist - Unrestricted File Upload
CVSS 9.8
CVE-2020-21786 CRITICAL
Ibos - Unrestricted File Upload
CVSS 9.8
CVE-2020-21787 CRITICAL
Crmeb - Unrestricted File Upload
CVSS 9.8
CVE-2020-19510 CRITICAL
Textpattern - Unrestricted File Upload
CVSS 9.8
CVE-2020-36388 HIGH
Civicrm < 5.21.3 - Unrestricted File Upload
CVSS 8.8
CVE-2020-35760 CRITICAL
Bloofoxcms - Unrestricted File Upload
CVSS 9.8
CVE-2020-7864 HIGH
Raonwiz DEXT5Editor <3.5.1405747.1100.03 - Command Injection
CVSS 7.8
CVE-2020-36141 HIGH
Bloofoxcms - Unrestricted File Upload
CVSS 8.8
CVE-2020-21005 MEDIUM
Wellcms - Unrestricted File Upload
CVSS 6.5
CVE-2020-35442 CRITICAL
Fangfa Fdcms - Unrestricted File Upload
CVSS 9.8
CVE-2020-26678 HIGH
vFairs 3.3 - RCE
CVSS 8.8
CVE-2020-23765 HIGH
Bludit <3.12.0 - Code Injection
CVSS 7.2
CVE-2020-18166 CRITICAL
LAOBANCMS v2.0 - File Upload
CVSS 9.8
CVE-2020-28063 CRITICAL
Articlecms - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium