CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2019-14451 CRITICAL
Repetier-Server 0.8-0.91 - RCE
CVSS 9.8
CVE-2019-18417 HIGH
Sourcecodester Restaurant Management System - Unrestricted File Upload
CVSS 8.8
CVE-2019-11021 HIGH
Schlix Cms - Unrestricted File Upload
CVSS 7.2
CVE-2019-16530 HIGH
Sonatype Nexus Repository Manager <2.14.15 & 3.x <3.19 - RCE
CVSS 7.2
CVE-2019-16700 CRITICAL
TYPO3 slub_events <3.0.2 - RCE
CVSS 9.8
CVE-2019-17536 MEDIUM
Gilacms Gila Cms < 1.11.4 - Unrestricted File Upload
CVSS 4.9
CVE-2019-17490 HIGH
Jnoj Jiangnan Online Judge - Unrestricted File Upload
CVSS 8.8
CVE-2019-17352 HIGH
Jfinal < 4.4 - Unrestricted File Upload
CVSS 7.5
CVE-2019-14657 HIGH
Yealink phones <2019-08-04 - RCE
CVSS 8.8
CVE-2019-14656 HIGH
Yealink phones <2019-08-04 - Privilege Escalation
CVSS 8.8
CVE-2019-15751 CRITICAL
Sitos Six - Unrestricted File Upload
CVSS 9.8
CVE-2019-15748 CRITICAL
Sitos Six - Unrestricted File Upload
CVSS 9.8
CVE-2019-17188 HIGH
Fecmall - Unrestricted File Upload
CVSS 7.2
CVE-2019-11655 HIGH
Micro Focus ArcSight Logger >=6.7.0 - Unrestricted File Upload
CVSS 8.8
CVE-2019-15766 HIGH
Kslabs Ksweb - Unrestricted File Upload
CVSS 8.8
CVE-2019-17046 HIGH
Ilch Cms - Unrestricted File Upload
CVSS 7.2
CVE-2019-15862 HIGH
CKFinder <2.6.2.1 - Info Disclosure
CVSS 7.5
CVE-2019-16720 HIGH
ZZZCMS zzzphp <1.7.2 - File Upload
CVSS 7.5
CVE-2019-14916 MEDIUM
Prise Adas - Unrestricted File Upload
CVSS 6.5
CVE-2019-14252 HIGH
Publisure 2.1.2 - Code Injection
CVSS 7.2
CVE-2019-15843 HIGH
Xiaomi Millet <6.3.9.3 - Info Disclosure
CVSS 7.4
CVE-2019-6839 HIGH
Schneider Electric U.motion Server - Unrestricted File Upload
CVSS 8.8
CVE-2019-15131 CRITICAL
Code42 < 6.7.5 - Unrestricted File Upload
CVSS 9.8
CVE-2019-8371 HIGH
Open-emr Openemr - Unrestricted File Upload
CVSS 7.2
CVE-2019-16318 HIGH
Pimcore <5.7.1 - Auth Bypass
CVSS 8.8
Details
Vulnerabilities 4,021
Exploit Likelihood Medium