CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-40553 MEDIUM
Tmall_demo v2024.07.03 - File Upload
CVSS 4.9
CVE-2024-5630 HIGH
WordPress Plugin <4.3 - RCE
CVSS 8.8
CVE-2024-6730 MEDIUM
Nanjing Xingyuantu Technology SparkShop <1.1.6 - Unrestricted Upload
CVSS 6.3
CVE-2024-5450 CRITICAL
Bug Library < 2.1.1 - Unrestricted File Upload
CVSS 9.1
CVE-2024-5080 HIGH
Tipsandtricks-hq WP Emember < 10.6.6 - Unrestricted File Upload
CVSS 8.8
CVE-2024-40551 HIGH
PublicCMS <4.0.202302.e - RCE
CVSS 8.8
CVE-2024-40550 HIGH
Public CMS <4.0.202302.e - RCE
CVSS 8.8
CVE-2024-40549 HIGH
PublicCMS <4.0.202302.e - RCE
CVSS 8.8
CVE-2024-40548 HIGH
PublicCMS <4.0.202302.e - RCE
CVSS 8.8
CVE-2024-40546 HIGH
PublicCMS <4.0.202302.e - RCE
CVSS 8.8
CVE-2024-40545 HIGH
PublicCMS <4.0.202302.e - RCE
CVSS 8.8
CVE-2024-38736 CRITICAL
Realtyna Organic IDX <4.14.13 - Code Injection
CVSS 9.1
CVE-2024-38734 CRITICAL
SpreadsheetConverter Import Spreadsheets from Microsoft Excel <10.1...
CVSS 9.1
CVE-2024-3112 MEDIUM
Quotes and Tips <1.45 - Privilege Escalation
CVSS 4.8
CVE-2024-5911 MEDIUM
Paloaltonetworks Pan-os < 10.1.9 - Unrestricted File Upload
CVSS 4.9
CVE-2024-6647 MEDIUM
Croogo <4.0.7 - Unrestricted Upload
CVSS 4.7
CVE-2024-39865 HIGH
Siemens Sinema Remote Connect Server < 3.2 - Unrestricted File Upload
CVSS 8.8
CVE-2024-37424 CRITICAL
Newspack Blocks <3.0.8 - RCE
CVSS 9.9
CVE-2024-37420 CRITICAL
WPZita Zita Elementor Site Library <1.6.1 - Code Injection
CVSS 9.9
CVE-2024-37418 CRITICAL
Church Admin < 4.4.7 - Unrestricted File Upload
CVSS 9.9
CVE-2024-6314 CRITICAL
IQ Testimonials <2.2.7 - File Upload
CVSS 9.8
CVE-2024-6313 CRITICAL
Gutenberg Forms <2.2.9 - RCE
CVSS 9.8
CVE-2024-6161 HIGH
Default Thumbnail Plus <1.0.2.3 - RCE
CVSS 8.8
CVE-2024-6123 HIGH
Bit Form plugin <2.13.3 - Code Injection
CVSS 7.2
CVE-2024-37555 CRITICAL
Zealousweb Generate Pdf Using Contact... - Unrestricted File Upload
CVSS 9.1
Details
Vulnerabilities 4,016
Exploit Likelihood Medium