CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2018-18315 HIGH
Mossle Lemon - Unrestricted File Upload
CVSS 7.5
CVE-2018-9206 CRITICAL
Blueimp jQuery-File-Upload <=9.22.0 - File Upload
CVSS 9.8
CVE-2018-18086 HIGH
Phome Empirecms - Unrestricted File Upload
CVSS 8.8
CVE-2018-17442 HIGH
D-Link Central WiFi Manager <1.03r0100-Beta1 - RCE
CVSS 8.8
CVE-2018-17440 CRITICAL
D-Link Central WiFi Manager <1.03r0100-Beta1 - RCE
CVSS 9.8
CVE-2018-15424 MEDIUM
Cisco Identity Services Engine - Improper Input Validation
CVSS 4.7
CVE-2018-17553 HIGH
Naviwebs Navigate CMS <2.8 - RCE
CVSS 8.8
CVE-2018-17573 CRITICAL
Wp-Insert <2.4.2 - Code Injection
CVSS 9.8
CVE-2018-17055 HIGH
Progress Sitefinity CMS <11.0 - File Upload
CVSS 7.5
CVE-2018-15961 CRITICAL KEV
Adobe Coldfusion - Unrestricted File Upload
CVSS 9.8
CVE-2018-16821 MEDIUM
SeaCMS 6.64 - Path Traversal
CVSS 5.3
CVE-2018-17139 HIGH
UltimatePOS 2.5 - RCE
CVSS 8.8
CVE-2018-16287 CRITICAL
LG Supersign Cms - Unrestricted File Upload
CVSS 9.8
CVE-2018-16796 HIGH
HiScout GRC Suite <3.1.5 - File Upload
CVSS 8.8
CVE-2018-16974 CRITICAL
Elefant CMS <2.0.7 - Code Injection
CVSS 9.8
CVE-2018-16388 HIGH
E107 - Unrestricted File Upload
CVSS 7.2
CVE-2018-16731 CRITICAL
CScms 4.1 - File Upload
CVSS 9.8
CVE-2018-0645 CRITICAL
Bit-part Mtappjquery < 1.8.1 - Unrestricted File Upload
CVSS 9.8
CVE-2018-1000658 HIGH
LimeSurvey <3.14.4 - RCE
CVSS 8.8
CVE-2018-16397 MEDIUM
Limesurvey < 3.14.7 - Unrestricted File Upload
CVSS 4.9
CVE-2018-16373 MEDIUM
Frog Cms - Unrestricted File Upload
CVSS 4.9
CVE-2018-16370 CRITICAL
Pescms Team - Unrestricted File Upload
CVSS 9.8
CVE-2018-16352 CRITICAL
Weaselcms - Unrestricted File Upload
CVSS 9.8
CVE-2018-15882 CRITICAL
Joomla! < 3.8.12 - Unrestricted File Upload
CVSS 9.8
CVE-2018-3832 CRITICAL
Insteon Hub 2245-222 Firmware - Unrestricted File Upload
CVSS 9.0
Details
Vulnerabilities 4,021
Exploit Likelihood Medium