CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-52370 CRITICAL
Hive Support - WordPress Help Desk <1.1.1 - Code Injection
CVSS 9.9
CVE-2024-52369 CRITICAL
Optimal Access Inc. KBucket <4.1.6 - RCE
CVSS 9.9
CVE-2024-52384 CRITICAL
Sage AI <2.4.9 - Unrestricted File Upload
CVSS 9.9
CVE-2024-52380 CRITICAL
Picsmize <1.0.0 - Code Injection
CVSS 10.0
CVE-2024-52379 CRITICAL
Kinetic Pay <2.0.8 - RCE
CVSS 10.0
CVE-2024-52377 CRITICAL
BdThemes Instant Image Generator <1.5.4 - RCE
CVSS 10.0
CVE-2024-52376 CRITICAL
cmsMinds Boat Rental Plugin <1.0.1 - RCE
CVSS 10.0
CVE-2024-52375 CRITICAL
Arttia Creative Datasets Manager <1.5 - RCE
CVSS 10.0
CVE-2024-52374 CRITICAL
DoThatTask <1.5.5 - RCE
CVSS 10.0
CVE-2024-52373 CRITICAL
Devexhub Gallery <2.0.1 - RCE
CVSS 10.0
CVE-2024-52372 CRITICAL
WebTechGlobal Easy CSV Importer <7.0.0 - Unrestricted File Upload
CVSS 10.0
CVE-2024-52302 HIGH
common-user-management - RCE
CVE-2024-11214 MEDIUM
Mayurik Best Employee Management System - Improper Access Control
CVSS 4.7
CVE-2024-11211 MEDIUM
Eyoucms < 1.6.7 - Improper Access Control
CVSS 4.7
CVE-2024-10820 CRITICAL
Vanquish Woocommerce Upload Files < 84.4 - Unrestricted File Upload
CVSS 9.8
CVE-2024-11138 LOW
Dedecms - Improper Access Control
CVSS 2.7
CVE-2024-11122 MEDIUM
51mis Lingdang Crm < 8.6.4.3 - Improper Access Control
CVSS 6.3
CVE-2024-11018 CRITICAL
Vice Webopac < 6.5.1 - Unrestricted File Upload
CVSS 9.8
CVE-2024-11017 HIGH
Vice Webopac < 6.5.1 - Unrestricted File Upload
CVSS 8.8
CVE-2024-51793 CRITICAL
Webful Creations Computer Repair Shop <3.8115 - RCE
CVSS 10.0
CVE-2024-51792 CRITICAL
Dang Ngoc Binh Audio Record <1.0 - RCE
CVSS 10.0
CVE-2024-51791 CRITICAL
Made I.T. Forms <2.8.0 - RCE
CVSS 10.0
CVE-2024-51790 CRITICAL
Team HB WEBSOL HB AUDIO GALLERY <3.0 - RCE
CVSS 10.0
CVE-2024-51789 CRITICAL
UjW0L Image Classify <1.0.0 - Code Injection
CVSS 10.0
CVE-2024-51788 CRITICAL
The Novel Design Store Directory <4.3.0 - Unrestricted Upload of Fi...
CVSS 10.0
Details
Vulnerabilities 4,016
Exploit Likelihood Medium