CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,014 vulnerabilities with CWE-434
CVE-2024-56054 CRITICAL
Vibethemes Wordpress Learning Managem... - Unrestricted File Upload
CVSS 9.1
CVE-2024-56052 CRITICAL
Vibethemes Wordpress Learning Managem... - Unrestricted File Upload
CVSS 9.9
CVE-2024-56050 CRITICAL
Vibethemes Wordpress Learning Managem... - Unrestricted File Upload
CVSS 9.9
CVE-2024-55514 MEDIUM
Raisecom Msg2300 Firmware - Unrestricted File Upload
CVSS 6.3
CVE-2024-54285 CRITICAL
SeedProd Pro <6.18.10 - RCE
CVSS 9.1
CVE-2024-54370 CRITICAL
SuitePlugins Video & Photo Gallery <1.1.0 - Code Injection
CVSS 9.9
CVE-2024-12478 MEDIUM
Invoiceplane < 1.6.1 - Improper Access Control
CVSS 6.3
CVE-2024-9698 HIGH
Crafthemes Demo Import <3.3 - File Upload
CVSS 7.2
CVE-2024-54262 CRITICAL
Siddharth Nagar Import Export For WooCommerce <1.5 - RCE
CVSS 9.9
CVE-2024-9290 CRITICAL
Super Backup & Clone - Migrate <2.3.3 - RCE
CVSS 9.8
CVE-2024-12042 MEDIUM
Inspireui Mstore API < 4.16.5 - XSS
CVSS 5.4
CVE-2024-10590 HIGH
Opt-In Downloads plugin for WordPress <4.07 - Command Injection
CVSS 8.8
CVE-2024-44220 MEDIUM
Apple Macos < 14.7.2 - Unrestricted File Upload
CVSS 5.5
CVE-2024-53677 CRITICAL
Apache Struts < 6.4.0 - Unrestricted File Upload
CVSS 9.8
CVE-2024-47946 HIGH
Poweruser Session - RCE
CVSS 7.2
CVE-2024-50625 HIGH
Digi Connectport Lts Firmware < 1.4.12 - Unrestricted File Upload
CVSS 8.0
CVE-2024-54918 CRITICAL
Lopalopa E-learning Management System - Unrestricted File Upload
CVSS 9.8
CVE-2024-53822 CRITICAL
Genetech Pie Register Premium <3.8.3.3 - Uplaod of File with Danger...
CVSS 10.0
CVE-2024-54214 CRITICAL
Roninwp Revy <1.18 - RCE
CVSS 10.0
CVE-2024-53811 MEDIUM
POSIMYTH WDesignkit <1.0.40 - RCE
CVSS 6.6
CVE-2024-10578 HIGH
Pubnews theme <1.0.7 - Privilege Escalation
CVSS 8.8
CVE-2024-12233 HIGH
Fabian Online Notice Board - Improper Access Control
CVSS 7.3
CVE-2024-51548 CRITICAL
ABB ASPECT <3.08.02, NEXUS Series <3.08.02, MATRIX Series <3.08.02 ...
CVSS 9.9
CVE-2024-53982 HIGH
ZOO-Project - Path Traversal
CVE-2024-40744 CRITICAL
Joomla <4.4.8 - File Upload
CVSS 9.8
Details
Vulnerabilities 4,014
Exploit Likelihood Medium