CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2019-8433 HIGH
Jtbc Php - Unrestricted File Upload
CVSS 7.5
CVE-2019-8394 MEDIUM KEV
Zohocorp Manageengine Servicedesk Plus - Unrestricted File Upload
CVSS 6.5
CVE-2019-8362 HIGH
Dedecms < 5.7 - Unrestricted File Upload
CVSS 7.5
CVE-2019-0259 CRITICAL
SAP Businessobjects - Unrestricted File Upload
CVSS 9.8
CVE-2019-7721 HIGH
nc-cms <3.5 - Code Injection
CVSS 7.5
CVE-2019-7684 CRITICAL
inxedu <2018-12-24 - Code Injection
CVSS 9.8
CVE-2019-6139 CRITICAL
Forcepoint User ID < 1.3.0 - Unrestricted File Upload
CVSS 9.8
CVE-2019-0017 MEDIUM
Juniper Junos Space - Unrestricted File Upload
CVSS 6.5
CVE-2019-5009 HIGH
Vtiger CRM 7.1.0 - Code Injection
CVSS 7.2
CVE-2018-25258 HIGH
RGui 3.5.0 Local Buffer Overflow SEH DEP Bypass
CVSS 8.4
CVE-2018-25171 HIGH
EdTv 2 - SQL Injection
CVSS 8.2
CVE-2018-25168 MEDIUM
Precurio Intranet Portal 2.0 - CSRF
CVSS 4.3
CVE-2018-25162 MEDIUM
2-Plan Team 1.0.4 - Authenticated RCE
CVSS 6.5
CVE-2018-25158 HIGH
Chamilo LMS 1.11.8 - Authenticated RCE
CVSS 8.8
CVE-2018-25114 CRITICAL
osCommerce Online Merchant <2.3.4.1 - RCE
CVE-2018-25019 HIGH
Learndash < 2.5.4 - Missing Authorization
CVSS 7.5
CVE-2018-21244 CRITICAL
Foxitsoftware Phantompdf < 8.3.6 - Unrestricted File Upload
CVSS 9.8
CVE-2018-21243 MEDIUM
Foxitsoftware Phantompdf < 8.3.6 - Unrestricted File Upload
CVSS 6.5
CVE-2018-19798 HIGH
Fleetco FMM <1.2 - RCE
CVSS 8.8
CVE-2018-17058 HIGH
JABA XPress Online Shop <2018-09-14 - Code Injection
CVSS 8.8
CVE-2018-18930 HIGH
Trms Carousel Digital Signage < 7.0.4.104 - Unrestricted File Upload
CVSS 8.8
CVE-2018-21024 CRITICAL
Centreon < 2.8.27 - Unrestricted File Upload
CVSS 9.8
CVE-2018-18572 HIGH
Oscommerce - Unrestricted File Upload
CVSS 7.2
CVE-2018-20926 MEDIUM
Cpanel < 62.0.42 - Unrestricted File Upload
CVSS 6.7
CVE-2018-20925 MEDIUM
Cpanel < 62.0.42 - Unrestricted File Upload
CVSS 6.7
Details
Vulnerabilities 4,021
Exploit Likelihood Medium