CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2020-0932 HIGH
Microsoft Sharepoint Enterprise Server - Unrestricted File Upload
CVSS 8.8
CVE-2020-0931 HIGH
Microsoft Business Productivity Servers - Unrestricted File Upload
CVSS 8.8
CVE-2020-0929 HIGH
Microsoft Sharepoint Enterprise Server - Unrestricted File Upload
CVSS 8.8
CVE-2020-0920 HIGH
Microsoft Sharepoint Enterprise Server - Unrestricted File Upload
CVSS 8.8
CVE-2020-10507 CRITICAL
School Manage System <2020 - RCE
CVSS 9.8
CVE-2020-11722 CRITICAL
Dungeon Crawl Stone Soup < 0.25 - Unrestricted File Upload
CVSS 9.8
CVE-2020-10621 CRITICAL
WebAccess/NMS <3.0.2 - Code Injection
CVSS 9.8
CVE-2020-11598 CRITICAL
Cipplanner Cipace < 9.1 - Missing Authentication
CVSS 9.8
CVE-2020-11544 HIGH
Projectworlds Official Car Rental System - Unrestricted File Upload
CVSS 7.2
CVE-2020-8639 HIGH
TestLink 1.9.20 - RCE
CVSS 8.8
CVE-2020-11451 HIGH
Microstrategy Web < 10.4 - Unrestricted File Upload
CVSS 7.2
CVE-2020-6008 CRITICAL
LifterLMS <3.37.15 - RCE
CVSS 9.8
CVE-2020-10964 CRITICAL
Serendipity <2.3.4 - RCE
CVSS 9.8
CVE-2020-10963 HIGH
FrozenNode Laravel-Administrator <5.0.12 - RCE
CVSS 7.2
CVE-2020-10934 HIGH
Acyba AcyMailing <6.9.2 - File Upload Vulnerability
CVSS 7.2
CVE-2020-8866 MEDIUM
Horde Groupware Webmail Edition 5.2.22 - RCE
CVSS 6.5
CVE-2020-8511 HIGH
Artica Pandora FMS <7.42 - RCE
CVSS 7.2
CVE-2020-7935 HIGH
Artica Pandora FMS <7.42 - RCE
CVSS 7.2
CVE-2020-10806 CRITICAL
eZ Publish Kernel <5.4.14.1,6.x<6.13.6.2,7.x<7.5.6.2 - RCE
CVSS 9.8
CVE-2020-10682 HIGH
CMS Made Simple 2.2.13 - RCE
CVSS 7.8
CVE-2020-9423 CRITICAL
Logicaldoc < 8.3.3 - Unrestricted File Upload
CVSS 9.8
CVE-2020-9472 MEDIUM
Umbraco Cms < 8.5.4 - Unrestricted File Upload
CVSS 6.5
CVE-2020-9471 HIGH
Umbraco Cms - Unrestricted File Upload
CVSS 8.8
CVE-2020-5844 HIGH
Pandora FMS v7.0 NG - Authenticated RCE
CVSS 7.2
CVE-2020-10557 HIGH
AContent <1.4 - Command Injection
CVSS 8.8
Details
Vulnerabilities 4,021
Exploit Likelihood Medium