CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-0916 CRITICAL
UvDesk Community <1.1.3 - RCE
CVSS 10.0
CVE-2024-31610 MEDIUM
Code-projects Simple School Managemen... - Unrestricted File Upload
CVSS 6.3
CVE-2024-31615 CRITICAL
Thinkcmf - Unrestricted File Upload
CVSS 9.8
CVE-2024-3508 MEDIUM
Bombastic - Code Injection
CVSS 4.3
CVE-2024-32954 CRITICAL
Tribulant Newsletters <4.9.5 - Unrestricted Upload
CVSS 9.1
CVE-2024-32836 CRITICAL
WP Lab WP-Lister Lite for eBay <3.5.11 - Unrestricted Upload of Fil...
CVSS 9.1
CVE-2024-28890 MEDIUM
Incsub Forminator < 1.29.0 - Unrestricted File Upload
CVSS 5.3
CVE-2024-29368 MEDIUM
MoziloCMS v2.0 - File Upload
CVSS 6.5
CVE-2024-29661 CRITICAL
DedeCMS <5.7 - RCE
CVSS 9.8
CVE-2024-23534 HIGH
Ivanti Avalanche < 6.4.3.528 - Unrestricted File Upload
CVSS 8.8
CVE-2024-3948 MEDIUM
Library System - Unrestricted File Upload
CVSS 6.3
CVE-2024-32161 CRITICAL
jizhiCMS 2.5 - File Upload
CVSS 9.8
CVE-2024-32514 CRITICAL
WP Poll Maker <3.4 - Info Disclosure
CVSS 9.9
CVE-2024-31680 HIGH
Shibang Communications Co., Ltd. IP Network Intercom Broadcasting System - File Upload
CVSS 8.8
CVE-2024-32256 HIGH
Phpgurukul Tourism Management System - Unrestricted File Upload
CVSS 8.1
CVE-2024-32254 HIGH
Phpgurukul Tourism Management System - Unrestricted File Upload
CVSS 8.8
CVE-2024-3863 CRITICAL
Mozilla Firefox < 115.10.0 - Unrestricted File Upload
CVSS 9.8
CVE-2024-3804 MEDIUM
Vesystem Cloud Desktop <20240408 - Unrestricted Upload
CVSS 6.3
CVE-2024-3803 MEDIUM
Vesystem Cloud Desktop <20240408 - Unrestricted Upload
CVSS 6.3
CVE-2024-3778 HIGH
AI3 Qbibot - Unrestricted File Upload
CVSS 7.2
CVE-2024-3736 MEDIUM
Cym1102 Nginxwebui < 4.2.4 - Unrestricted File Upload
CVSS 4.3
CVE-2024-3705 HIGH
Opengnsys - Unrestricted File Upload
CVSS 8.8
CVE-2024-3344 MEDIUM
Otter Blocks - XSS
CVSS 6.4
CVE-2024-31214 CRITICAL
Traccar < 5.12 - Unrestricted File Upload
CVSS 9.6
CVE-2024-2221 CRITICAL
qdrant/qdrant - Path Traversal
CVSS 9.8
Details
Vulnerabilities 4,016
Exploit Likelihood Medium