CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,021 vulnerabilities with CWE-434
CVE-2018-1000646 HIGH
LibreHealthIO LH-EHR REL-2.0.0 - Auth Bypass
CVSS 8.8
CVE-2018-15573 HIGH
Reprisesoftware Reprise License Manager - Unrestricted File Upload
CVSS 8.8
CVE-2018-12256 HIGH
LiteCart <2.1.3 - Authenticated RCE
CVSS 8.8
CVE-2018-15139 HIGH
OpenEMR <5.0.1.4 - Code Injection
CVSS 8.8
CVE-2018-14028 HIGH
WordPress 4.9.7 - Code Injection
CVSS 7.2
CVE-2018-15137 CRITICAL
CeLa Link CLR-M20 - RCE
CVSS 9.8
CVE-2018-14857 HIGH
OCS Inventory NG - RCE
CVSS 8.8
CVE-2018-14911 HIGH
ukcms <1.1.7 - File Upload
CVSS 7.2
CVE-2018-12468 CRITICAL
Micro Focus GroupWise <18.0.2 - RCE
CVSS 9.1
CVE-2018-12940 HIGH
Seeddms < 5.1.8 - Unrestricted File Upload
CVSS 8.8
CVE-2018-14570 HIGH
Niushop B2C Multi-business basic V1.11 - RCE
CVSS 8.8
CVE-2018-14441 CRITICAL
cckevincyh SSH CompanyWebsite <2018-05-03 - File Upload
CVSS 9.8
CVE-2018-14334 CRITICAL
joyplus-cms 1.6.0 - File Upload
CVSS 9.8
CVE-2018-13981 CRITICAL
Zeta-producer Zeta Producer Desktop Cms - Unrestricted File Upload
CVSS 9.8
CVE-2018-12980 HIGH
Wago 762-3000 Firmware < 02 - Unrestricted File Upload
CVSS 8.8
CVE-2018-1000619 HIGH
Ovidentia <8.4.3 - Authenticated RCE
CVSS 8.8
CVE-2018-11638 HIGH
Dialogic Powermedia Xms < 3.5 - Unrestricted File Upload
CVSS 7.2
CVE-2018-12426 CRITICAL
WP Live Chat Support Pro <8.0.07 - RCE
CVSS 9.8
CVE-2018-12528 HIGH
Intex N150 - Info Disclosure
CVSS 8.1
CVE-2018-13038 CRITICAL
Opendesa Opensid - Unrestricted File Upload
CVSS 9.8
CVE-2018-13024 HIGH
Metinfo - Unrestricted File Upload
CVSS 7.2
CVE-2018-13021 HIGH
Hongcms - Unrestricted File Upload
CVSS 7.2
CVE-2018-12914 CRITICAL
Publiccms - Unrestricted File Upload
CVSS 9.8
CVE-2018-1000544 CRITICAL
rubyzip <1.2.1 - Path Traversal
CVSS 9.8
CVE-2018-0571 MEDIUM
Basercms < 3.0.15 - Unrestricted File Upload
CVSS 4.3
Details
Vulnerabilities 4,021
Exploit Likelihood Medium