CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-45137 HIGH
InDesign Desktop <19.4, 18.5.3 - RCE
CVSS 7.8
CVE-2024-45136 HIGH
InCopy <19.4, 18.5.3 - RCE
CVSS 7.8
CVE-2024-47823 CRITICAL
Livewire <2.12.7-3.5.2 - Code Injection
CVSS 9.8
CVE-2024-37179 HIGH
SAP Businessobjects Business Intelligence - Unrestricted File Upload
CVSS 7.7
CVE-2024-47319 HIGH
Bit Apps Bit Form - Contact Form <2.13.10 - Code Injection
CVSS 8.0
CVE-2024-9417 MEDIUM
Hashthemes Hash Form < 1.2.0 - Unrestricted File Upload
CVSS 6.1
CVE-2024-8743 MEDIUM
Bit File Manager <6.5.7 - XSS
CVSS 6.8
CVE-2024-37869 HIGH
Emiloimagtolis Online Discussion Forum - Unrestricted File Upload
CVSS 8.8
CVE-2024-37868 HIGH
Emiloimagtolis Online Discussion Forum - Unrestricted File Upload
CVSS 8.8
CVE-2024-47655 HIGH
Shilpi Client Dashboard - RCE
CVSS 8.8
CVE-2024-45965 MEDIUM
Contao < 4.13.54 - Unrestricted File Upload
CVSS 6.4
CVE-2024-7855 HIGH
Thimpress WP Hotel Booking < 2.1.3 - Unrestricted File Upload
CVSS 8.8
CVE-2024-47528 MEDIUM
LibreNMS - XSS
CVSS 4.8
CVE-2024-9108 CRITICAL
Wechat Social login plugin <1.3.0 - Code Injection
CVSS 9.8
CVE-2024-46441 HIGH
YPay 1.2.0 - RCE
CVSS 8.8
CVE-2024-9280 MEDIUM
Kvf-admin - Unrestricted File Upload
CVSS 4.7
CVE-2024-9278 MEDIUM
HuankeMao SCRM <0.0.3 - Unrestricted Upload
CVSS 4.7
CVE-2024-47169 HIGH
Agnai <1.0.330 - RCE
CVSS 8.8
CVE-2024-8725 MEDIUM
WordPress - XSS
CVSS 6.8
CVE-2024-8126 HIGH
Advanced File Manager <5.2.8 - RCE
CVSS 7.5
CVE-2024-7772 CRITICAL
Artbees Jupiter X Core < 4.6.6 - Unrestricted File Upload
CVSS 9.8
CVE-2024-8940 CRITICAL
Scriptcase - Unrestricted File Upload
CVSS 10.0
CVE-2024-46101 CRITICAL
Gdidees Cms < 3.9.1 - Unrestricted File Upload
CVSS 9.8
CVE-2024-9038 MEDIUM
Codezips Online Shopping Portal - Unrestricted File Upload
CVSS 4.3
CVE-2024-9036 MEDIUM
Angeljudesuarez Online Book Store Project - Unrestricted File Upload
CVSS 6.3
Details
Vulnerabilities 4,016
Exploit Likelihood Medium