CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,016 vulnerabilities with CWE-434
CVE-2023-4311 HIGH
Vrm 360 3D Model Viewer <1.2.1 - Code Injection
CVSS 8.8
CVE-2023-6902 MEDIUM
Codelyfe Stupid Simple Cms < 1.2.4 - Unrestricted File Upload
CVSS 5.5
CVE-2023-6887 MEDIUM
Forestblog < 2022-06-30 - Unrestricted File Upload
CVSS 6.3
CVE-2023-6850 MEDIUM
Kodcloud Kodexplorer < 4.52.01 - Unrestricted File Upload
CVSS 6.3
CVE-2023-48394 HIGH
Kaifa Technology WebITR - RCE
CVSS 8.8
CVE-2023-6827 HIGH
G5plus Essential Real Estate < 4.3.5 - Unrestricted File Upload
CVSS 7.5
CVE-2023-6826 HIGH
E2pdf < 1.20.25 - Unrestricted File Upload
CVSS 7.2
CVE-2023-48376 CRITICAL
Csharp Cws Collaborative Development ... - Unrestricted File Upload
CVSS 9.8
CVE-2023-48371 CRITICAL
Itpison Omicard Edm - Unrestricted File Upload
CVSS 9.8
CVE-2023-50564 HIGH
Pluck - Unrestricted File Upload
CVSS 8.8
CVE-2023-6794 MEDIUM
Paloaltonetworks Pan-os < 8.1.26 - Unrestricted File Upload
CVSS 5.5
CVE-2023-6723 CRITICAL
Europeana Repox - Unrestricted File Upload
CVSS 10.0
CVE-2023-4122 CRITICAL
Imsurajghosh Student Information System - Unrestricted File Upload
CVSS 9.9
CVE-2023-6576 MEDIUM
Byzoro S210 <20231123 - Unrestricted Upload
CVSS 6.3
CVE-2023-6574 MEDIUM
Byzoro Smart S20 <20231120 - Unrestricted Upload
CVSS 6.3
CVE-2023-39539 HIGH
AMI Aptio V - Improper Input Validation
CVSS 7.5
CVE-2023-39538 HIGH
AMI Aptio V - Improper Input Validation
CVSS 7.5
CVE-2023-48930 CRITICAL
xinhu xinhuoa <2.2.1 - File Upload
CVSS 9.8
CVE-2023-40460 HIGH
Sierrawireless Aleos < 4.16.0 - XSS
CVSS 7.1
CVE-2023-5953 HIGH
Welcart E-commerce < 2.9.5 - Unrestricted File Upload
CVSS 8.8
CVE-2023-48966 HIGH
ThinkAdmin <6.1.53 - RCE
CVSS 8.8
CVE-2023-48965 HIGH
ThinkAdmin <6.1.53 - RCE
CVSS 8.8
CVE-2023-5637 HIGH
Arslansoft Education Portal < 1.1 - Unrestricted File Upload
CVSS 7.5
CVE-2023-5636 CRITICAL
Arslansoft Education Portal < 1.1 - Unrestricted File Upload
CVSS 9.8
CVE-2023-6449 MEDIUM
Contact Form 7 <5.8.3 - File Upload
CVSS 6.6
Details
Vulnerabilities 4,016
Exploit Likelihood Medium