CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,013 vulnerabilities with CWE-434
CVE-2024-57169 CRITICAL
Soplanning - Unrestricted File Upload
CVSS 9.8
CVE-2024-54525 HIGH
Apple Ipados < 18.2 - Unrestricted File Upload
CVSS 8.8
CVE-2024-13359 HIGH
WooCommerce <1.12.0 - RCE
CVSS 8.1
CVE-2024-13882 HIGH
Coderevolution Aiomatic < 2.3.9 - Unrestricted File Upload
CVSS 8.8
CVE-2024-13908 HIGH
Bestwebsoft SMTP < 1.2.0 - Unrestricted File Upload
CVSS 7.2
CVE-2024-47259 LOW
VAPIX API - Command Injection
CVSS 3.5
CVE-2024-8425 CRITICAL
WooCommerce Ultimate Gift Card <2.6.0 - RCE
CVSS 9.8
CVE-2024-41340 HIGH
Draytek Vigor165 Firmware < 4.2.7 - Unrestricted File Upload
CVSS 8.4
CVE-2024-41339 HIGH
Draytek Vigor165 Firmware < 4.2.7 - Unrestricted File Upload
CVSS 8.8
CVE-2024-56897 CRITICAL
YI Car Dashcam <3.88 - Info Disclosure
CVSS 9.8
CVE-2024-13869 HIGH
Wpvivid Backup & Migration < 0.9.113 - Unrestricted File Upload
CVSS 7.2
CVE-2024-10960 CRITICAL
Brizy < 2.6.5 - Unrestricted File Upload
CVSS 9.9
CVE-2024-13365 CRITICAL
CleanTalk plugin <2.149 - RCE
CVSS 9.8
CVE-2024-13714 HIGH
All-Images.ai - IA Image Bank <1.0.4 - RCE
CVSS 8.8
CVE-2024-13544 MEDIUM
Amini7 Zarinpal Paid Download < 2.3 - Unrestricted File Upload
CVSS 4.8
CVE-2024-13011 CRITICAL
WP Foodbakery <4.7 - File Upload
CVSS 9.8
CVE-2024-57408 HIGH
Beian.miit Cool-admin-java - Unrestricted File Upload
CVSS 7.2
CVE-2024-57407 HIGH
Timo v2.0.3 - RCE
CVSS 7.3
CVE-2024-57668 HIGH
Fabian Shopping Portal - Unrestricted File Upload
CVSS 8.8
CVE-2024-13723 HIGH
Checkmk - RCE
CVSS 7.2
CVE-2024-57968 CRITICAL KEV
Advantive Veracore < 2024.4.2.1 - Unrestricted File Upload
CVSS 9.9
CVE-2024-57450 CRITICAL
1000mz Chestnutcms < 1.5.0 - Unrestricted File Upload
CVSS 9.8
CVE-2024-55417 MEDIUM
Thecontrolgroup Voyager < 1.8.0 - Unrestricted File Upload
CVSS 4.3
CVE-2024-13448 CRITICAL
ThemeREX Addons <2.32.3 - File Upload
CVSS 9.8
CVE-2024-40693 HIGH
IBM Planning Analytics 2.0-2.1 - Code Injection
CVSS 8.0
Details
Vulnerabilities 4,013
Exploit Likelihood Medium