CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,019 vulnerabilities with CWE-434
CVE-2020-1024 HIGH
Microsoft SharePoint - RCE
CVSS 8.8
CVE-2020-1023 HIGH
Microsoft SharePoint - RCE
CVSS 8.8
CVE-2020-12828 CRITICAL
AnchorFree VPN SDK <1.3.3.218 - Code Injection
CVSS 9.8
CVE-2020-13241 HIGH
Microweber 1.1.18 - Unrestricted File Upload
CVSS 7.8
CVE-2020-11807 HIGH
Sourcefabric Newscoop - Unrestricted File Upload
CVSS 7.8
CVE-2020-12255 HIGH
Rconfig - Unrestricted File Upload
CVSS 8.8
CVE-2020-13128 HIGH
Manolo GWTUpload 1.0.3 - DoS
CVSS 7.5
CVE-2020-13126 CRITICAL
Elementor Pro <2.9.4 - RCE
CVSS 9.9
CVE-2020-5577 HIGH
Movable Type <7.2.1, <6.5.3, <6.3.11 - Path Traversal
CVSS 8.8
CVE-2020-11108 HIGH
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
CVSS 8.8
CVE-2020-5880 HIGH
Om BIG-IP <15.0.1.3-14.1.2.3 - File Upload
CVSS 7.1
CVE-2020-11943 HIGH
Opmantek Open-audit - Unrestricted File Upload
CVSS 8.8
CVE-2020-12252 MEDIUM
Gigamon Gigavue < 5.4.04 - Unrestricted File Upload
CVSS 6.2
CVE-2020-11817 CRITICAL
Rukovoditel - Unrestricted File Upload
CVSS 9.8
CVE-2020-12077 HIGH
Mappress < 2.53.9 - Unrestricted File Upload
CVSS 8.8
CVE-2020-7055 CRITICAL
Elementor Page Builder < 2.7.4 - Unrestricted File Upload
CVSS 9.9
CVE-2020-11011 CRITICAL
Phproject <1.7.8 - RCE
CVSS 9.9
CVE-2020-10569 CRITICAL
SysAid On-Premise 20.1.11 - Unauthenticated RCE
CVSS 9.8
CVE-2020-11815 CRITICAL
Rukovoditel - Unrestricted File Upload
CVSS 9.8
CVE-2020-11811 CRITICAL
Qdpm - Unrestricted File Upload
CVSS 9.8
CVE-2020-9280 HIGH
Silverstripe < 4.5.0 - Unrestricted File Upload
CVSS 7.5
CVE-2020-0974 HIGH
Microsoft Sharepoint Enterprise Server - Unrestricted File Upload
CVSS 8.8
CVE-2020-0971 HIGH
Microsoft Sharepoint Enterprise Server - Unrestricted File Upload
CVSS 8.8
CVE-2020-0932 HIGH
Microsoft Sharepoint Enterprise Server - Unrestricted File Upload
CVSS 8.8
CVE-2020-0931 HIGH
Microsoft Business Productivity Servers - Unrestricted File Upload
CVSS 8.8
Details
Vulnerabilities 4,019
Exploit Likelihood Medium