CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,012 vulnerabilities with CWE-434
CVE-2025-32202 CRITICAL
Brian Batt - elearningfreak.com - Unrestricted File Upload
CVSS 9.1
CVE-2025-32140 CRITICAL
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
CVSS 9.9
CVE-2025-31002 CRITICAL
Bogdan Bendziukov Squeeze - Unrestricted Upload
CVSS 9.1
CVE-2025-29394 HIGH
verydows <2.0 - RCE
CVSS 8.1
CVE-2025-27082 HIGH
AOS-10 GW/AOS-8 - Arbitrary File Write
CVSS 7.2
CVE-2025-32028 CRITICAL
PSU Haxcms-php < 10.0.3 - Unrestricted File Upload
CVSS 9.9
CVE-2025-3410 MEDIUM
Aias - Improper Access Control
CVSS 6.3
CVE-2025-2525 HIGH
Streamit theme <4.0.1 - RCE
CVSS 8.8
CVE-2025-3325 MEDIUM
iteaj iboot 1.1.3 - Auth Bypass
CVSS 4.3
CVE-2025-3324 MEDIUM
Nimrod 0.8 - Unrestricted Upload
CVSS 6.3
CVE-2025-32370 HIGH
Kentico Xperience < 13.0.178 - XSS
CVSS 7.2
CVE-2025-1500 MEDIUM
IBM Maximo Application Suite < 9.0.7 - Unrestricted File Upload
CVSS 5.5
CVE-2025-32118 CRITICAL
NiteoThemes CMP - Unrestricted Upload
CVSS 9.1
CVE-2025-3244 MEDIUM
Senior-walter Web-based Pharmacy Product Management System - Improper Access Control
CVSS 6.3
CVE-2025-2780 HIGH
Xtendify Woffice < 5.4.22 - Unrestricted File Upload
CVSS 8.8
CVE-2025-3169 MEDIUM
Projeqtor <12.0.2 - Unrestricted Upload
CVSS 5.0
CVE-2025-3123 MEDIUM
Wondercms - Improper Access Control
CVSS 4.7
CVE-2025-2005 CRITICAL
Etoilewebdesign Front End Users < 3.2.32 - Unrestricted File Upload
CVSS 9.8
CVE-2025-27692 MEDIUM
Dell Wyse Management Suite < 5.1 - Unrestricted File Upload
CVSS 4.7
CVE-2025-2891 HIGH
The Real Estate 7 WordPress theme - File Upload
CVSS 8.8
CVE-2025-2008 HIGH
WordPress <7.19 - File Upload
CVSS 8.8
CVE-2025-3042 MEDIUM
Projectworlds Online Time Table Generator - Improper Access Control
CVSS 6.3
CVE-2025-3041 MEDIUM
Projectworlds Online Time Table Generator - Improper Access Control
CVSS 6.3
CVE-2025-3040 MEDIUM
Projectworlds Online Time Table Generator - Improper Access Control
CVSS 6.3
CVE-2025-31577 MEDIUM
Appointify <1.0.8 - RCE
CVSS 6.6
Details
Vulnerabilities 4,012
Exploit Likelihood Medium