CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-0757 MEDIUM
WordPress Plugin <4.3000000023 - Code Injection
CVSS 5.4
CVE-2024-29974 CRITICAL
Zyxel NAS326 <V5.21(AAZF.17)C0 - RCE
CVSS 9.8
CVE-2024-29848 HIGH
Ivanti Avalanche <6.4.x - Command Injection
CVSS 7.2
CVE-2024-22060 MEDIUM
Ivanti Neurons for ITSM - File Upload
CVSS 4.9
CVE-2024-5518 MEDIUM
Emiloimagtolis Online Discussion Forum - Unrestricted File Upload
CVSS 6.3
CVE-2024-3412 CRITICAL
WP STAGING WordPress Backup Plugin - File Upload
CVSS 9.1
CVE-2024-22641 HIGH
TCPDF <6.6.5 - DoS
CVSS 7.5
CVE-2024-35510 CRITICAL
Dedecms - Unrestricted File Upload
CVSS 9.8
CVE-2024-5377 HIGH
SourceCodester Vehicle Management System 1.0 - Unrestricted Upload
CVSS 7.3
CVE-2024-35593 MEDIUM
Raingad IM <4.1.4 - Code Injection
CVSS 5.5
CVE-2024-1332 MEDIUM
Brainstormforce Custom Fonts < 2.1.5 - XSS
CVSS 6.4
CVE-2024-5247 HIGH
Netgear Prosafe Network Management System - Unrestricted File Upload
CVSS 8.8
CVE-2024-35570 CRITICAL
Inxedu - Unrestricted File Upload
CVSS 9.8
CVE-2024-35375 CRITICAL
Dedecms - Unrestricted File Upload
CVSS 9.8
CVE-2024-35080 CRITICAL
Inxedu - Unrestricted File Upload
CVSS 9.8
CVE-2024-35079 CRITICAL
Inxedu - Unrestricted File Upload
CVSS 9.8
CVE-2024-5084 CRITICAL
Hashthemes Hash Form < 1.1.1 - Unrestricted File Upload
CVSS 9.8
CVE-2024-5145 MEDIUM
SourceCodester Vehicle Management System <1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-5050 MEDIUM
Wangshen SecGate 3600 - Unrestricted Upload
CVSS 6.3
CVE-2024-5049 MEDIUM
Codezips E-commerce Site - Unrestricted File Upload
CVSS 6.3
CVE-2024-5047 HIGH
Kabir-m-alhasan Student Management System - Unrestricted File Upload
CVSS 7.3
CVE-2024-34982 CRITICAL
Lylme Spage - Unrestricted File Upload
CVSS 9.8
CVE-2024-5043 MEDIUM
Emlog - Unrestricted File Upload
CVSS 4.7
CVE-2024-32809 CRITICAL
JumpDEMAND Inc. ActiveDEMAND <0.2.41 - Unrestricted Upload
CVSS 10.0
CVE-2024-33556 HIGH
8theme Xstore Core < 5.3.9 - Unrestricted File Upload
CVSS 8.2
Details
Vulnerabilities 4,016
Exploit Likelihood Medium