CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2024-24809 HIGH
Traccar - Unrestricted File Upload
CVSS 8.5
CVE-2024-3521 MEDIUM
Byzoro Smart S80 Management Platform <20240317 - Unrestricted Upload
CVSS 4.7
CVE-2024-2334 MEDIUM
Template Kit - Import plugin <1.0.14 - XSS
CVSS 6.4
CVE-2024-2125 HIGH
EnvíaloSimple: Email Marketing y Newsletters - CSRF
CVSS 8.8
CVE-2024-31454 MEDIUM
NPM Psitransfer < 2.2.0 - Unrestricted File Upload
CVSS 6.5
CVE-2024-31453 MEDIUM
NPM Psitransfer < 2.2.0 - Unrestricted File Upload
CVSS 6.5
CVE-2024-3444 MEDIUM
Wangshen SecGate 3600 <20240408 - Unrestricted Upload
CVSS 4.7
CVE-2024-3437 HIGH
Fast5 Prison Management System - Unrestricted File Upload
CVSS 7.3
CVE-2024-3436 MEDIUM
Fast5 Prison Management System - Unrestricted File Upload
CVSS 6.3
CVE-2024-31345 CRITICAL
Sukhchain Singh Auto Poster <1.2 - Unrestricted Upload
CVSS 9.1
CVE-2024-31292 HIGH
Moove Agency Import XML/RSS Feeds <2.1.5 - Unrestricted Upload
CVSS 7.2
CVE-2024-31286 CRITICAL
J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus <8.6.03.005 - Unr...
CVSS 9.9
CVE-2024-31280 CRITICAL
Church Admin < 4.1.6 - Unrestricted File Upload
CVSS 9.9
CVE-2024-3369 MEDIUM
code-projects Car Rental 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-31210 HIGH
Wordpress < 4.1.40 - Unrestricted File Upload
CVSS 7.6
CVE-2024-29387 HIGH
projeqtor <11.2.0 - RCE
CVSS 8.8
CVE-2024-28520 MEDIUM
Byzoro Networks Smart <S210 - Info Disclosure
CVSS 6.5
CVE-2024-3022 HIGH
Reputeinfosystems Bookingpress < 1.0.87 - Unrestricted File Upload
CVSS 7.2
CVE-2024-27951 CRITICAL
Themeisle Multiple Page Generator < 3.4.1 - Unrestricted File Upload
CVSS 9.1
CVE-2024-31012 CRITICAL
Sem-cms Semcms - Unrestricted File Upload
CVSS 9.8
CVE-2024-29514 HIGH
lepton <7.1.0 - Authenticated RCE
CVSS 8.8
CVE-2024-3129 MEDIUM
SourceCodester Image Accordion Gallery App 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-30533 HIGH
Techeshta Layouts for Elementor <1.8 - Unrestricted Upload
CVSS 7.5
CVE-2024-31115 CRITICAL
QuanticaLabs Chauffeur Taxi Booking System <7.2 - Unrestricted Uplo...
CVSS 10.0
CVE-2024-31114 CRITICAL
biplob018 Shortcode Addons <3.2.5 - RCE
CVSS 9.1
Details
Vulnerabilities 4,016
Exploit Likelihood Medium