CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,013 vulnerabilities with CWE-434
CVE-2025-22782 CRITICAL
Web Ready Now WR Price List Manager For Woocommerce <1.0.9 - Code I...
CVSS 9.9
CVE-2025-0463 MEDIUM
51mis Lingdang Crm - Improper Access Control
CVSS 6.3
CVE-2025-0460 HIGH
Blog Botz for Journal Theme 1.0 - Unrestricted Upload
CVSS 7.3
CVE-2025-0394 HIGH
Groundhogg <3.7.3.5 - RCE
CVSS 8.8
CVE-2025-0057 MEDIUM
SAP NetWeaver AS JAVA - XSS
CVSS 4.8
CVE-2025-0402 MEDIUM
reggie 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-0399 MEDIUM
StarSea99 starsea-mall 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-22152 CRITICAL
Atheos <v600 - Code Injection
CVSS 9.1
CVE-2025-22504 CRITICAL
jumpdemand 4ECPS Web Forms <0.2.18 - RCE
CVSS 10.0
CVE-2025-0346 MEDIUM
code-projects CMS 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-0341 MEDIUM
Campcodes Computer Laboratory Management System - Improper Access Control
CVSS 6.3
CVE-2025-0335 MEDIUM
code-projects Online Bike Rental System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-22137 CRITICAL
Pingvin Share <1.4.0 - Code Injection
CVSS 9.8
CVE-2025-22133 CRITICAL
WeGIA <3.2.8 - Code Injection
CVSS 9.9
CVE-2025-22132 HIGH
WeGIA <3.2.7 - XSS
CVSS 8.3
CVE-2025-21624 CRITICAL
Oxygenz Clipbucket < 5.5.1-239 - Unrestricted File Upload
CVSS 9.8
CVE-2025-0213 MEDIUM
Campcodes Project Management System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-22389 HIGH
Optimizely Cms < 12.32.0 - Unrestricted File Upload
CVSS 8.0
CVE-2024-50620 HIGH
CIPPlanner CIPAce <9.17 - Unrestricted Upload of File with Dangerou...
CVSS 8.8
CVE-2024-27480 CRITICAL
givanz VvvebJs <1.7.2 - Info Disclosure
CVSS 9.8
CVE-2024-25182 CRITICAL
givanz VvvebJs <1.7.2 - File Upload
CVSS 9.8
CVE-2024-44599 HIGH
FNT Command <13.4.0 - Path Traversal
CVSS 8.3
CVE-2024-44598 HIGH
FNT Command 13.4.0 - Code Injection
CVSS 8.8
CVE-2024-58313 HIGH
Xbtitfm - Unrestricted File Upload
CVSS 7.2
CVE-2024-58298 CRITICAL
Compuware iStrobe Web 20.13 - RCE
Details
Vulnerabilities 4,013
Exploit Likelihood Medium