CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2018-19612 HIGH
Westermo DR-250/DR-260 <5162 - RCE
CVSS 8.8
CVE-2018-4063 HIGH KEV
Sierrawireless Aleos < 4.4.9 - Unrestricted File Upload
CVSS 8.8
CVE-2018-19453 HIGH
Kentico CMS <11.0.45 - File Upload
CVSS 8.8
CVE-2018-20526 CRITICAL
Roxyfileman Roxy Fileman - Unrestricted File Upload
CVSS 9.8
CVE-2018-19514 CRITICAL
Webgalamb <7.0 - RCE
CVSS 9.8
CVE-2018-17418 HIGH
Monstra CMS <3.0.4 - RCE
CVSS 7.2
CVE-2018-20063 HIGH
Gurock TestRail 5.6.0.3853 - Unrestricted Upload of File
CVSS 8.8
CVE-2018-1969 CRITICAL
IBM Security Identity Manager 6.0.0 - Info Disclosure
CVSS 9.0
CVE-2018-16169 HIGH
Cybozu Remote Service Manager < 3.1.0 - Unrestricted File Upload
CVSS 8.8
CVE-2018-20166 HIGH
Rukovoditel 2.3.1 - Code Injection
CVSS 8.8
CVE-2018-5204 CRITICAL
ML Report <2.18.628.5980 - RCE
CVSS 9.8
CVE-2018-15333 MEDIUM
BIG-IP >=11.2.1 - Info Disclosure
CVSS 5.5
CVE-2018-7836 CRITICAL
IIoT Monitor 3.1.38 - Code Injection
CVSS 9.8
CVE-2018-1000839 HIGH
LH-EHR <REL-2_0_0 - RCE
CVSS 8.8
CVE-2018-1000811 HIGH
bludit <3.0.0 - RCE
CVSS 8.8
CVE-2018-19789 MEDIUM
Symfony <4.2.1 - Info Disclosure
CVSS 5.3
CVE-2018-6152 CRITICAL
Google Chrome <66.0.3359.117 - Code Injection
CVSS 9.6
CVE-2018-16097 MEDIUM
Lenovo Xclarity Integrator < 3.5 - Unrestricted File Upload
CVSS 6.5
CVE-2018-16093 MEDIUM
Lenovo Xclarity Integrator < 5.5 - Unrestricted File Upload
CVSS 6.5
CVE-2018-15537 HIGH
Ocsinventory-ng Ocsinventory NG - Unrestricted File Upload
CVSS 8.8
CVE-2018-19692 CRITICAL
tp5cms <2017-05-25 - RCE
CVSS 9.8
CVE-2018-17936 CRITICAL
Nuuo Cms < 3.3 - Unrestricted File Upload
CVSS 9.8
CVE-2018-19562 HIGH
PHPok <4.9.015 - RCE
CVSS 8.8
CVE-2018-19550 HIGH
Interspire Email Marketer <6.1.6 - File Upload
CVSS 8.8
CVE-2018-19537 HIGH
TP-Link Archer C5 - RCE
CVSS 7.2
Details
Vulnerabilities 4,021
Exploit Likelihood Medium