CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,017 vulnerabilities with CWE-434
CVE-2023-5144 MEDIUM
D-Link DAR-7000/DAR-8000 <= 20151231 - Unrestricted Upload
CVSS 6.3
CVE-2023-40183 HIGH
Dataease < 1.18.11 - Unrestricted File Upload
CVSS 7.5
CVE-2023-42335 HIGH
Fl3xx Crew - Unrestricted File Upload
CVSS 8.8
CVE-2023-42331 HIGH
Elitecms Elite Cms - Unrestricted File Upload
CVSS 8.8
CVE-2023-43497 HIGH
Jenkins <2.423 - Info Disclosure
CVSS 8.1
CVE-2023-43478 HIGH
Telstra Smart Modem Gen 2 - RCE
CVSS 8.8
CVE-2023-41902 HIGH
Corecode Macupdater < 2.3.8 - Unrestricted File Upload
CVSS 7.8
CVE-2023-43619 HIGH
Croc <9.6.5 - Info Disclosure
CVSS 7.8
CVE-2023-38887 HIGH
Dolibarr ERP CRM <17.0.1 - RCE
CVSS 8.8
CVE-2023-36319 HIGH
Openupload Stable <0.4.3 - RCE
CVSS 8.8
CVE-2023-5034 MEDIUM
MY Food Recipe - Unrestricted File Upload
CVSS 6.3
CVE-2023-41626 MEDIUM
Gradio v3.27.0 - File Upload
CVSS 4.8
CVE-2023-4988 MEDIUM
Laiketui - Unrestricted File Upload
CVSS 6.3
CVE-2023-42180 HIGH
Lenosp < 1.2.0 - Unrestricted File Upload
CVSS 8.8
CVE-2023-30962 MEDIUM
Gotham Cerberus - XSS
CVSS 6.8
CVE-2023-40784 CRITICAL
DedeCMS 5.7.102 - File Upload
CVSS 9.8
CVE-2023-2071 CRITICAL
Rockwellautomation Factorytalk View < 13.0 - Improper Input Validation
CVSS 9.8
CVE-2023-40731 MEDIUM
QMS Automotive <V12.39 - Code Injection
CVSS 5.7
CVE-2023-42472 HIGH
SAP Businessobjects Business Intellig... - Unrestricted File Upload
CVSS 8.7
CVE-2023-41564 MEDIUM
Cockpit CMS <2.6.3 - RCE
CVSS 6.1
CVE-2023-39424 CRITICAL
Resortdata Internet Reservation Module Next Generation - Injection
CVSS 9.9
CVE-2023-41009 CRITICAL
Adlered Bolo-Solo 2.6 - RCE
CVSS 9.8
CVE-2023-3375 HIGH
Unisign Bookreen <3.0.0 - Code Injection
CVSS 7.2
CVE-2023-41108 HIGH
TEF portal <2023-07-17 - Authenticated RCE
CVSS 8.8
CVE-2023-4739 MEDIUM
Byzoro Smart S85f Firmware < 20230820 - Unrestricted File Upload
CVSS 6.3
Details
Vulnerabilities 4,017
Exploit Likelihood Medium