CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,014 vulnerabilities with CWE-434
CVE-2024-51208 HIGH
Phpgurukul Boat Booking System - Unrestricted File Upload
CVSS 7.2
CVE-2024-11404 MEDIUM
django Filer <3.3 - Basic XSS
CVSS 5.5
CVE-2024-51743 HIGH
MarkUs <2.4.8 - Code Injection
CVSS 8.8
CVE-2024-51499 HIGH
Markus < 2.4.8 - Unrestricted File Upload
CVSS 8.8
CVE-2024-52429 CRITICAL
Antonhoelstad WP Quick Setup < 2.0 - Unrestricted File Upload
CVSS 9.9
CVE-2024-11315 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11314 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11313 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11312 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11311 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-52397 CRITICAL
Davor Zeljkovic Convert Docx2post <1.4 - RCE
CVSS 9.1
CVE-2024-52408 CRITICAL
PushAssist Push Notifications <3.0.8 - RCE
CVSS 9.9
CVE-2024-52407 CRITICAL
codeSavory BasePress <1.0.0 - RCE
CVSS 9.9
CVE-2024-52406 CRITICAL
Wibergs Web CSV <3.04 - RCE
CVSS 9.9
CVE-2024-52405 CRITICAL
Bikram Joshi B-Banner Slider <1.1 - RCE
CVSS 9.9
CVE-2024-52404 CRITICAL
Bigfive CF7 Reply Manager <1.2.3 - Uplaod of File with Dangerous Type
CVSS 9.9
CVE-2024-52403 CRITICAL
WPExperts User Management <1.1 - RCE
CVSS 9.9
CVE-2024-52400 CRITICAL
Subhasis Laha Gallerio <1.01 - RCE
CVSS 9.9
CVE-2024-52399 CRITICAL
Clarisse K. Writer Helper <3.1.6 - RCE
CVSS 9.9
CVE-2024-52398 CRITICAL
Halyra CDI <5.5.3 - Uplaod of File with Danger
CVSS 9.1
CVE-2024-8856 CRITICAL
WordPress WP Time Capsule Arbitrary File Upload to RCE
CVSS 9.8
CVE-2024-9849 HIGH
Real 3D FlipBook WordPress Plugin <4.6 - RCE
CVSS 8.8
CVE-2024-50652 MEDIUM
Geeeeeeeek Java Shop - Unrestricted File Upload
CVSS 4.3
CVE-2024-52370 CRITICAL
Hive Support - WordPress Help Desk <1.1.1 - Code Injection
CVSS 9.9
CVE-2024-52369 CRITICAL
Optimal Access Inc. KBucket <4.1.6 - RCE
CVSS 9.9
Details
Vulnerabilities 4,014
Exploit Likelihood Medium