CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-40125 CRITICAL
CLESS Server <4.5.2 - RCE
CVSS 9.8
CVE-2024-46377 CRITICAL
Mayurik Best House Rental Management System - Unrestricted File Upload
CVSS 9.8
CVE-2024-46373 HIGH
Dedecms - Unrestricted File Upload
CVSS 8.8
CVE-2024-45398 HIGH
Contao <4.13.49, 5.3.15, 5.4.3 - Code Injection
CVSS 8.3
CVE-2024-8242 MEDIUM
MStore API - WordPress <4.15.3 - File Upload
CVSS 4.3
CVE-2024-27115 CRITICAL
SOPlanning - Remote Code Execution
CVSS 9.8
CVE-2024-8232 HIGH
SpiderControl SCADA Web Server - File Upload
CVSS 7.5
CVE-2024-44871 HIGH
MoziloCMS v3.0 - RCE
CVSS 7.2
CVE-2024-7770 HIGH
Bitapps File Manager < 6.5.6 - Unrestricted File Upload
CVSS 8.8
CVE-2024-44849 CRITICAL
Qualitor <8.24 - RCE
CVSS 9.8
CVE-2024-7620 MEDIUM
Fastlinemedia Customizer Export/import - Unrestricted File Upload
CVSS 6.6
CVE-2024-45171 HIGH
za-internet C-MOR Video Surveillance 5.2401 - Code Injection
CVSS 8.8
CVE-2024-8463 CRITICAL
PHPGurukul Job Portal 1.0 - Authenticated RCE
CVSS 9.9
CVE-2024-45076 CRITICAL
IBM webMethods Integration 10.15 - Code Injection
CVSS 9.9
CVE-2024-42991 HIGH
MCMS <5.4.1 - RCE
CVSS 8.1
CVE-2024-8342 MEDIUM
SourceCodester Petshop Management System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-8341 MEDIUM
SourceCodester Petshop Management System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-8338 MEDIUM
HFO4 shudong-share 2.4.7 - Unrestricted Upload
CVSS 6.3
CVE-2024-8330 HIGH
6SHR system from Gether Technology - RCE
CVSS 8.8
CVE-2024-8296 MEDIUM
FeehiCMS <2.1.1 - Unrestricted Upload
CVSS 6.3
CVE-2024-8295 MEDIUM
FeehiCMS <2.1.1 - Unrestricted Upload
CVSS 6.3
CVE-2024-8294 MEDIUM
FeehiCMS <2.1.1 - Unrestricted Upload
CVSS 6.3
CVE-2024-6311 HIGH
Funnelforms Free <3.7.3.2 - RCE
CVSS 7.2
CVE-2024-8170 LOW
SourceCodester Zipped Folder Manager App 1.0 - Unrestricted Upload
CVSS 3.5
CVE-2024-8166 MEDIUM
Ruijie EG2000K 11.1(6)B2 - Unrestricted Upload
CVSS 4.7
Details
Vulnerabilities 4,016
Exploit Likelihood Medium