CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,011 vulnerabilities with CWE-434
CVE-2025-10051 HIGH
Demo Import Kit <1.1.0 - RCE
CVSS 7.2
CVE-2025-10041 CRITICAL
Flex QR Code Generator <1.2.5 - File Upload
CVSS 9.8
CVE-2025-61678 HIGH
FreePBX <16.0.92-17.0.6 - Authenticated File Upload
CVE-2025-37132 HIGH
Arubanetworks Arubaos < 8.10.0.19 - Unrestricted File Upload
CVSS 7.2
CVE-2025-42910 CRITICAL
SAP Supplier Relationship Management - File Upload
CVSS 9.0
CVE-2025-11675 HIGH
Enterprise Cloud Database - Code Injection
CVSS 7.2
CVE-2025-11660 HIGH
Oranbyte School Management System - Improper Access Control
CVSS 7.3
CVE-2025-11659 HIGH
Oranbyte School Management System - Improper Access Control
CVSS 7.3
CVE-2025-11658 HIGH
Oranbyte School Management System - Improper Access Control
CVSS 7.3
CVE-2025-11657 HIGH
Oranbyte School Management System - Improper Access Control
CVSS 7.3
CVE-2025-11656 HIGH
Oranbyte School Management System - Improper Access Control
CVSS 7.3
CVE-2025-11655 MEDIUM
Total.js Flow <673ef9144dd25d4f4fd4fdfda5af27f230198924 - Unrestric...
CVSS 4.7
CVE-2025-6553 CRITICAL
Ovatheme Events Manager <1.8.5 - File Upload
CVSS 9.8
CVE-2025-35055 HIGH
Newforma Project Center < 2023.1 - Path Traversal
CVSS 8.8
CVE-2025-11508 MEDIUM
Fabian Voting System - Improper Access Control
CVSS 4.7
CVE-2025-11470 MEDIUM
Nikhil-bhalerao Hotel And Lodge Management System - Improper Access Control
CVSS 4.7
CVE-2025-11436 MEDIUM
JhumanJ OpnForm <1.9.3 - Unrestricted Upload
CVSS 6.3
CVE-2025-11426 MEDIUM
Advanced Library Management System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-11417 MEDIUM
Campcodes Advanced Online Voting System - Improper Access Control
CVSS 6.3
CVE-2025-11398 MEDIUM
Nikhil-bhalerao Hotel And Lodge Management System - Improper Access Control
CVSS 6.3
CVE-2025-11354 MEDIUM
Fabian Online Hotel Reservation System - Improper Access Control
CVSS 6.3
CVE-2025-11353 MEDIUM
Fabian Online Hotel Reservation System - Improper Access Control
CVSS 6.3
CVE-2025-11352 MEDIUM
Fabian Online Hotel Reservation System - Improper Access Control
CVSS 6.3
CVE-2025-11351 MEDIUM
Fabian Online Hotel Reservation System - Improper Access Control
CVSS 6.3
CVE-2025-11347 HIGH
code-projects Student Crud Operation <3.3 - Unrestricted Upload
CVSS 7.3
Details
Vulnerabilities 4,011
Exploit Likelihood Medium