CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,014 vulnerabilities with CWE-434
CVE-2024-40693 HIGH
IBM Planning Analytics 2.0-2.1 - Code Injection
CVSS 8.0
CVE-2024-25034 HIGH
IBM Planning Analytics <2.2 - Code Injection
CVSS 8.0
CVE-2024-55926 HIGH
Xerox Workplace Suite - Info Disclosure
CVSS 7.6
CVE-2024-13091 CRITICAL
WPBot Pro Wordpress Chatbot <13.5.4 - File Upload
CVSS 9.8
CVE-2024-51919 CRITICAL
Fancy Product Designer <6.4.3 - Uplaod of File with Dangerous Type
CVSS 9.0
CVE-2024-13333 HIGH
WordPress Advanced File Manager <5.2.13 - RCE
CVSS 7.5
CVE-2024-40513 MEDIUM
themesebrand Chatvia <5.3.2 - RCE
CVSS 4.6
CVE-2024-13355 MEDIUM
WooCommerce: OrderConvo <13.2 - RCE/XSS
CVSS 5.4
CVE-2024-41454 MEDIUM
Process Maker pm4core-docker <4.1.21-RC7 - RCE
CVSS 6.5
CVE-2024-57761 HIGH
Huayi-tec Jeewms < 2025-01-01 - Unrestricted File Upload
CVSS 8.1
CVE-2024-48760 CRITICAL
Gestioip - Unrestricted File Upload
CVSS 9.8
CVE-2024-13171 HIGH
Ivanti EPM - Remote Code Execution
CVSS 7.8
CVE-2024-46479 CRITICAL
Venki Supravizio Bpm < 18.0.1 - Unrestricted File Upload
CVSS 9.9
CVE-2024-42180 LOW
Hcltech Dryice Myxalytics - Unrestricted File Upload
CVSS 1.6
CVE-2024-46210 HIGH
Redaxo - Unrestricted File Upload
CVSS 7.2
CVE-2024-43662 MEDIUM
Iocharger AC <24120701 - File Upload
CVE-2024-43657 HIGH
Iocharger AC <24120701 - Command Injection
CVSS 8.8
CVE-2024-43656 HIGH
Iocharger AC model chargers <24120701 - Command Injection
CVSS 8.8
CVE-2024-13212 MEDIUM
SingMR HouseRent 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-13210 MEDIUM
donglight bookstore <1.0 - Unrestricted Upload
CVSS 4.7
CVE-2024-13201 MEDIUM
wander-chu SpringBoot-Blog 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2024-13191 MEDIUM
ZeroWdd myblog 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-12854 HIGH
Garden Gnome Package <2.3.0 - Code Injection
CVSS 8.8
CVE-2024-12853 HIGH
Wpchill Modula Image Gallery < 2.11.11 - Unrestricted File Upload
CVSS 8.8
CVE-2024-53345 HIGH
Car Rental Management System <1.4 - Authenticated RCE
CVSS 8.8
Details
Vulnerabilities 4,014
Exploit Likelihood Medium