CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2019-15936 CRITICAL
Intesync Solismed 3.3sp - Insecure File Upload
CVSS 9.8
CVE-2019-4612 HIGH
IBM Planning Analytics 2.0 - Code Injection
CVSS 8.8
CVE-2019-19684 HIGH
nopCommerce v4.2.0 - Privilege Escalation
CVSS 8.8
CVE-2019-19595 CRITICAL
PrestaShop <4.8 - RCE
CVSS 9.8
CVE-2019-19594 CRITICAL
Adobe Stock API Integration - RCE
CVSS 9.8
CVE-2019-11216 MEDIUM
BMC Remedy Smart Reporting < 9.1.03.001 - XXE
CVSS 6.5
CVE-2019-19576 CRITICAL
verot.net class.upload <2.0.4 - Info Disclosure
CVSS 9.8
CVE-2019-4130 HIGH
IBM Cloud Pak System - Unrestricted File Upload
CVSS 8.8
CVE-2019-19020 HIGH
TitanHQ WebTitan <5.18 - RCE
CVSS 7.2
CVE-2019-19493 MEDIUM
Kentico <12.0.50 - XSS
CVSS 5.4
CVE-2019-19468 HIGH
Free Photo Viewer <1.3 - RCE
CVSS 7.8
CVE-2019-17403 HIGH
Nokia Impact < 18a - Unrestricted File Upload
CVSS 8.8
CVE-2019-12409 CRITICAL
Apache Solr < 8.3.0 - Unrestricted File Upload
CVSS 9.8
CVE-2019-12271 CRITICAL
Sandline Centraleyezer - Info Disclosure
CVSS 9.8
CVE-2019-19084 MEDIUM
Octopus Deploy <2019.10.4 - Info Disclosure
CVSS 4.3
CVE-2019-17058 CRITICAL
Footy Tipping Software - Unrestricted File Upload
CVSS 9.1
CVE-2019-14467 HIGH
Social Photo Gallery plugin 1.0 - WordPress - RCE
CVSS 7.8
CVE-2019-18952 CRITICAL
SibSoft Xfilesharing <2.5.1 - Code Injection
CVSS 9.8
CVE-2019-1443 MEDIUM
Microsoft Sharepoint Enterprise Server - Unrestricted File Upload
CVSS 6.5
CVE-2019-12719 CRITICAL
AUO Sunveillance Monitoring System & ... - Unrestricted File Upload
CVSS 9.8
CVE-2019-8140 MEDIUM
Magento < 2.2.10 - Unrestricted File Upload
CVSS 4.9
CVE-2019-8114 HIGH
Magento < 1.9.4.3 - Unrestricted File Upload
CVSS 7.2
CVE-2019-8093 HIGH
Magento < 2.2.10 - Unrestricted File Upload
CVSS 8.8
CVE-2019-17325 MEDIUM
Clipsoft Rexpert < 1.0.0.527 - Unrestricted File Upload
CVSS 6.5
CVE-2019-18204 HIGH
Zucchetti Infobusiness < 4.4.1 - Unrestricted File Upload
CVSS 8.8
Details
Vulnerabilities 4,021
Exploit Likelihood Medium