CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-40645 HIGH
FOG - RCE
CVSS 8.8
CVE-2024-7277 MEDIUM
Adonesevangelista Restaurant Manageme... - Unrestricted File Upload
CVSS 4.7
CVE-2024-38529 CRITICAL
Admidio <4.3.10 - RCE
CVSS 9.0
CVE-2024-7192 MEDIUM
Angeljudesuarez Society Management System - Unrestricted File Upload
CVSS 6.3
CVE-2024-7189 MEDIUM
Kevinwong Online Food Ordering System - Unrestricted File Upload
CVSS 6.3
CVE-2024-6366 CRITICAL
User Profile Builder <3.11.8 - Info Disclosure
CVSS 9.1
CVE-2024-42054 MEDIUM
Cervantes - Unrestricted File Upload
CVSS 5.4
CVE-2024-6431 HIGH
Media.net Ads Manager <2.10.13 - RCE
CVSS 8.8
CVE-2024-40318 HIGH
Webkul Qloapps <1.6.0.0 - Code Injection
CVSS 7.2
CVE-2024-6756 HIGH
Social Auto Poster 5.3.14 - RCE
CVSS 8.8
CVE-2024-6828 HIGH
Redux Framework <4.4.17 - XSS/Code Injection
CVSS 7.2
CVE-2024-6958 MEDIUM
Angeljudesuarez University Management... - Unrestricted File Upload
CVSS 6.3
CVE-2024-6948 MEDIUM
Gargaj Wuhu < 2024-02-10 - Unrestricted File Upload
CVSS 6.3
CVE-2024-6945 MEDIUM
Flute - Unrestricted File Upload
CVSS 6.3
CVE-2024-40400 HIGH
Automad v2.0.0 - Code Injection
CVSS 8.8
CVE-2024-3242 HIGH
Brizy < 2.4.45 - Unrestricted File Upload
CVSS 8.8
CVE-2024-20296 MEDIUM
Cisco ISE - File Upload
CVSS 4.7
CVE-2024-27311 MEDIUM
Zohocorp ManageEngine DDI Central <4001 - Path Traversal
CVSS 5.5
CVE-2024-31411 HIGH
Apache Streampipes < 0.95.0 - Unrestricted File Upload
CVSS 8.8
CVE-2024-6220 CRITICAL
Keydatas plugin <2.5.2 - RCE
CVSS 9.8
CVE-2024-6801 MEDIUM
Online Student Management System - Unrestricted File Upload
CVSS 6.3
CVE-2024-6595 LOW
GitLab CE/EE <16.11.6/<17.0.4/<17.1.2 - Info Disclosure
CVSS 3.0
CVE-2024-40394 CRITICAL
Simple Library Management System <1.0 - File Upload
CVSS 9.8
CVE-2024-40425 CRITICAL
Nanjin Xingyuantu Technology Co Sparkshop <1.1.6 - RCE
CVSS 9.8
CVE-2024-40555 MEDIUM
Tmall_demo v2024.07.03 - File Upload
CVSS 5.3
Details
Vulnerabilities 4,016
Exploit Likelihood Medium