CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,017 vulnerabilities with CWE-434
CVE-2023-40980 CRITICAL
DWSurvey <3.2.0 - RCE
CVSS 9.8
CVE-2023-41638 HIGH
GruppoSCAI RealGimm <1.1.37p38 - RCE
CVSS 8.8
CVE-2023-41637 CRITICAL
GruppoSCAI RealGimm <1.1.37p38 - RCE
CVSS 9.8
CVE-2023-4596 CRITICAL
Forminator <1.24.6 - File Upload
CVSS 9.8
CVE-2023-40825 HIGH
Perfree PerfreeBlog <3.1.2 - RCE
CVSS 7.2
CVE-2023-38029 CRITICAL
Saho Adm-100fp Firmware - Unrestricted File Upload
CVSS 9.8
CVE-2023-4559 MEDIUM
Bettershop LaikeTui - Unrestricted Upload
CVSS 6.3
CVE-2023-32757 CRITICAL
Edetw U-office Force - Unrestricted File Upload
CVSS 9.8
CVE-2023-24517 MEDIUM
Pandora FMS <v767 - RCE
CVSS 6.4
CVE-2023-38836 HIGH
BoidCMS Command Injection
CVSS 8.8
CVE-2023-4409 MEDIUM
Nbs&happysoftwechat - Unrestricted File Upload
CVSS 6.3
CVE-2023-39970 CRITICAL
Acyba Acymailing Starter < 8.5.0 - Unrestricted File Upload
CVSS 9.8
CVE-2023-31946 HIGH
Online Travel Agency System <1.0 - RCE
CVSS 7.2
CVE-2023-31941 HIGH
Online Travel Agency System <1.0 - RCE
CVSS 7.2
CVE-2023-39115 CRITICAL
Campcodes Online Matrimonial Website System Script <3.3 - XSS
CVSS 9.8
CVE-2023-38915 CRITICAL
Wolf-leo EasyAdmin8 <1.0 - RCE
CVSS 9.8
CVE-2023-28482 MEDIUM
Tigergraph Enterprise 3.7.0 - Info Disclosure
CVSS 6.5
CVE-2023-28480 MEDIUM
Tigergraph Enterprise 3.7.0 - Privilege Escalation
CVSS 6.5
CVE-2023-32564 CRITICAL
Ivanti Avalanche < 6.4.1 - Unrestricted File Upload
CVSS 9.8
CVE-2023-32562 CRITICAL
Ivanti Avalanche < 6.4.1 - Unrestricted File Upload
CVSS 9.8
CVE-2023-39776 CRITICAL
Phpjabbers Ticket Support Script - Unrestricted File Upload
CVSS 9.8
CVE-2023-4243 HIGH
FULL - Customer <2.2.3 - RCE
CVSS 8.8
CVE-2023-4186 MEDIUM
Pharmacy Management System - Unrestricted File Upload
CVSS 6.3
CVE-2023-39346 HIGH
Renjikai Linuxasmcallgraph < 2022-02-08 - Unrestricted File Upload
CVSS 8.8
CVE-2023-4159 HIGH
Omeka S < 4.0.3 - Unrestricted File Upload
CVSS 8.8
Details
Vulnerabilities 4,017
Exploit Likelihood Medium