CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-7987 HIGH
Rockwell Automation ThinManager ThinServer - RCE
CVSS 7.8
CVE-2024-8164 MEDIUM
Beikeshop < 1.5.5 - Improper Access Control
CVSS 6.3
CVE-2024-42523 HIGH
publiccms <V4.0.202302.e - Any File Upload
CVSS 7.2
CVE-2024-7559 HIGH
Filemanagerpro.io File Manager Pro < 8.3.7 - Code Injection
CVSS 8.8
CVE-2024-8089 MEDIUM
SourceCodester E-Commerce System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-39717 HIGH KEV
Versa-networks Versa Director - Unrestricted File Upload
CVSS 7.2
CVE-2024-42767 HIGH
Kashipara Hotel Management System v1.0 - RCE
CVSS 7.2
CVE-2024-7384 HIGH
Acymailing < 9.8.0 - Unrestricted File Upload
CVSS 7.5
CVE-2024-42780 HIGH
Kashipara Music Management System <1.0 - RCE
CVSS 8.8
CVE-2024-42779 HIGH
Kashipara Music Management System <1.0 - RCE
CVSS 8.8
CVE-2024-42778 HIGH
Kashipara Music Management System <1.0 - RCE
CVSS 8.8
CVE-2024-42777 CRITICAL
Kashipara Music Mgmt <1.0 - RCE
CVSS 9.8
CVE-2024-42563 CRITICAL
ERP <44bd04 - Code Injection
CVSS 9.8
CVE-2024-7944 MEDIUM
Adonesevangelista Laravel Property Ma... - Unrestricted File Upload
CVSS 6.3
CVE-2024-7943 MEDIUM
Adonesevangelista Laravel Property Ma... - Unrestricted File Upload
CVSS 6.3
CVE-2024-43249 CRITICAL
Bit Apps Bit Form Pro <2.6.4 - Command Injection
CVSS 9.9
CVE-2024-7917 MEDIUM
Douco Douphp - Unrestricted File Upload
CVSS 4.7
CVE-2024-7910 MEDIUM
Online Railway Reservation System - Unrestricted File Upload
CVSS 4.7
CVE-2024-7906 MEDIUM
Dedebiz - Unrestricted File Upload
CVSS 6.3
CVE-2024-7905 MEDIUM
Dedebiz - Unrestricted File Upload
CVSS 6.3
CVE-2024-7904 MEDIUM
Dedebiz - Unrestricted File Upload
CVSS 6.3
CVE-2024-7903 MEDIUM
Dedebiz - Unrestricted File Upload
CVSS 6.3
CVE-2024-42676 HIGH
Huizhi Enterprise Resource Management <1.0 - RCE
CVSS 8.8
CVE-2024-39397 CRITICAL
Adobe Commerce < 2.4.3 - Unrestricted File Upload
CVSS 9.0
CVE-2024-4389 HIGH
Depicter Slider/Carousel <3.1.1 - RCE
CVSS 8.8
Details
Vulnerabilities 4,016
Exploit Likelihood Medium