CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,017 vulnerabilities with CWE-434
CVE-2023-43838 HIGH
Personal Management System <1.4.64 - RCE
CVSS 7.8
CVE-2023-44974 CRITICAL
Emlog - Unrestricted File Upload
CVSS 9.8
CVE-2023-44973 CRITICAL
Emlog - Unrestricted File Upload
CVSS 9.8
CVE-2023-4817 HIGH
ICPDAS ET-7060 Firmware - Unrestricted File Upload
CVSS 7.2
CVE-2023-4097 HIGH
Qsige - Unrestricted File Upload
CVSS 8.8
CVE-2023-44009 CRITICAL
mojoPortal <2.7.0.0 - RCE
CVSS 9.8
CVE-2023-44008 CRITICAL
mojoPortal <2.7.0.0 - RCE
CVSS 9.8
CVE-2023-5227 CRITICAL
Phpmyfaq < 3.1.8 - Unrestricted File Upload
CVSS 9.8
CVE-2023-5284 MEDIUM
Engineers Online Portal - Unrestricted File Upload
CVSS 6.3
CVE-2023-5277 MEDIUM
Engineers Online Portal - Unrestricted File Upload
CVSS 6.3
CVE-2023-5262 MEDIUM
Openrapid Rapidcms - Unrestricted File Upload
CVSS 6.3
CVE-2023-5185 CRITICAL
Gym Management System Project v1.0 - RCE
CVSS 9.1
CVE-2023-43740 HIGH
Online Book Store Project v1.0 - RCE
CVSS 8.8
CVE-2023-43226 HIGH
DedeCMS <5.7.111 - RCE
CVSS 8.8
CVE-2023-38874 HIGH
gugoan's Economizzer v.0.9-beta1 - RCE
CVSS 8.8
CVE-2023-42462 HIGH
Glpi < 10.0.10 - Path Traversal
CVSS 7.7
CVE-2023-40219 HIGH
Welcart E-commerce < 2.8.21 - Unrestricted File Upload
CVSS 7.2
CVE-2023-39377 HIGH
Siberiancms < 4.20.44 - Unrestricted File Upload
CVSS 7.2
CVE-2023-5154 MEDIUM
D-Link DAR-8000 <20151231 - Unrestricted Upload
CVSS 6.3
CVE-2023-5150 MEDIUM
D-Link DAR-7000/DAR-8000 <20151231 - Unrestricted Upload
CVSS 6.3
CVE-2023-5149 MEDIUM
D-Link DAR-7000 <20151231 - Unrestricted Upload
CVSS 6.3
CVE-2023-5148 MEDIUM
D-Link DAR-7000/DAR-8000 <20151231 - Unrestricted Upload
CVSS 6.3
CVE-2023-5147 MEDIUM
D-Link DAR-7000 <20151231 - Unrestricted Upload
CVSS 6.3
CVE-2023-5146 MEDIUM
D-Link DAR-7000/DAR-8000 <20151231 - Unrestricted Upload
CVSS 6.3
CVE-2023-5145 MEDIUM
D-Link DAR-7000 <20151231 - Unrestricted Upload
CVSS 6.3
Details
Vulnerabilities 4,017
Exploit Likelihood Medium