CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,017 vulnerabilities with CWE-434
CVE-2023-6449 MEDIUM
Contact Form 7 <5.8.3 - File Upload
CVSS 6.6
CVE-2023-5966 MEDIUM
Espocrm < 7.5.2 - Unrestricted File Upload
CVSS 4.7
CVE-2023-5965 MEDIUM
Espocrm < 7.5.2 - Unrestricted File Upload
CVSS 4.7
CVE-2023-49052 HIGH
Microweber <2.0.4 - RCE
CVSS 8.8
CVE-2023-4226 HIGH
Chamilo LMS <= 1.11.24 - RCE
CVSS 8.8
CVE-2023-4225 HIGH
Chamilo LMS <= 1.11.24 - RCE
CVSS 8.8
CVE-2023-4224 HIGH
Chamilo LMS <= 1.11.24 - RCE
CVSS 8.8
CVE-2023-4223 HIGH
Chamilo LMS <= 1.11.24 - RCE
CVSS 8.8
CVE-2023-4220 HIGH
Chamilo v1.11.24 Unrestricted File Upload PHP Webshell
CVSS 8.1
CVE-2023-6219 HIGH
BookingPress <1.0.76 - File Upload
CVSS 7.2
CVE-2023-29770 HIGH
Sapplica Sentrifugo - Unrestricted File Upload
CVSS 8.8
CVE-2023-5604 CRITICAL
Asgaros Forum < 2.7.1 - Code Injection
CVSS 9.8
CVE-2023-41998 CRITICAL
Arcserve Udp < 9.2 - Unrestricted File Upload
CVSS 9.8
CVE-2023-6308 MEDIUM
Four-faith Video Surveillance Management System - Unrestricted File Upload
CVSS 6.3
CVE-2023-6274 MEDIUM
Byzoro Smart S80 <20231108 - Unrestricted Upload
CVSS 6.3
CVE-2023-41812 MEDIUM
Artica Pandora Fms < 774 - Unrestricted File Upload
CVSS 5.7
CVE-2023-41788 HIGH
Artica Pandora Fms < 774 - Unrestricted File Upload
CVSS 7.6
CVE-2023-5822 HIGH
Codedropz Drag And Drop Multiple File... - Unrestricted File Upload
CVSS 8.1
CVE-2023-6187 HIGH
Paid Memberships Pro <2.12.3 - Code Injection
CVSS 7.5
CVE-2023-39548 HIGH
NEC Expresscluster X - Unrestricted File Upload
CVSS 8.8
CVE-2023-48031 CRITICAL
Opensupports - Unrestricted File Upload
CVSS 9.8
CVE-2023-6133 MEDIUM
Forminator <1.27.0 - File Upload
CVSS 6.6
CVE-2023-48217 HIGH
Statamic < 3.4.14 - Code Injection
CVSS 8.8
CVE-2023-6127 MEDIUM
Salesagility Suitecrm < 7.12.14 - Unrestricted File Upload
CVSS 5.4
CVE-2023-47621 HIGH
Duncanmcclean Guest Entries < 3.1.3 - Unrestricted File Upload
CVSS 8.8
Details
Vulnerabilities 4,017
Exploit Likelihood Medium