CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,017 vulnerabilities with CWE-434
CVE-2023-34736 HIGH
Guantang Equipment Management System - Unrestricted File Upload
CVSS 7.2
CVE-2023-32526 MEDIUM
Trendmicro Mobile Security - Unrestricted File Upload
CVSS 6.5
CVE-2023-32525 MEDIUM
Trendmicro Mobile Security - Unrestricted File Upload
CVSS 6.5
CVE-2023-33404 CRITICAL
BlogEngine.Net <3.3.8.0 - RCE
CVSS 9.8
CVE-2023-36630 HIGH
CloudPanel <2.3.1 - Privilege Escalation/Authentication Bypass
CVSS 8.8
CVE-2023-1721 CRITICAL
Yoga Class Registration System <1.0 - Command Injection
CVSS 9.1
CVE-2023-27083 HIGH
Pluck CMS <4.7.16-dev5 - RCE
CVSS 7.2
CVE-2023-36097 CRITICAL
funadmin <3.3.3 - Insecure File Upload
CVSS 9.8
CVE-2023-35808 HIGH
Sugarcrm < 11.0.6 - Unrestricted File Upload
CVSS 8.8
CVE-2023-3295 HIGH
Unlimited-elements Unlimited Elements... - Unrestricted File Upload
CVSS 8.8
CVE-2023-34660 MEDIUM
Jeecg Boot - Unrestricted File Upload
CVSS 6.5
CVE-2023-34845 MEDIUM
Bludit - Unrestricted File Upload
CVSS 5.4
CVE-2023-32753 CRITICAL
Itpison Omicard Edm - Unrestricted File Upload
CVSS 9.8
CVE-2023-32752 CRITICAL
L7-networks Instantqos - Unrestricted File Upload
CVSS 9.8
CVE-2023-34833 MEDIUM
Thinkadmin - Unrestricted File Upload
CVSS 6.1
CVE-2023-3274 MEDIUM
Supplier Management System - Unrestricted File Upload
CVSS 6.3
CVE-2023-34747 CRITICAL
Ujcms - Unrestricted File Upload
CVSS 9.8
CVE-2023-34944 CRITICAL
Chamilo Lms < 1.11.18 - Unrestricted File Upload
CVSS 9.8
CVE-2023-31541 CRITICAL
CKEditor v1.2.3 - File Upload
CVSS 9.8
CVE-2023-3049 CRITICAL
TMT Lockcell <15 - Command Injection
CVSS 9.8
CVE-2023-33253 HIGH
LabCollector 6.0-6.15 - RCE
CVSS 8.8
CVE-2023-3187 MEDIUM
PHPGurukul Teachers Record Management System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2023-27881 HIGH
PTC Vuforia Studio < 9.9 - Unrestricted File Upload
CVSS 8.0
CVE-2023-33498 HIGH
alist <3.16.3 - Info Disclosure
CVSS 8.8
CVE-2023-33601 HIGH
phpok <6.4.100 - RCE
CVSS 8.8
Details
Vulnerabilities 4,017
Exploit Likelihood Medium