CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,010 vulnerabilities with CWE-434
CVE-2025-67260 HIGH
Terrapack TkWebCoreNG 1.0.20200914 - Code Injection
CVSS 8.8
CVE-2025-13462 LOW
Python tarfile - Path Traversal
CVE-2025-13067 HIGH
Royal Addons for Elementor <=1.7.1049 - RCE
CVSS 8.8
CVE-2025-68555 CRITICAL
zozothemes Nutrie <2.0.1 - File Upload
CVSS 9.9
CVE-2025-68554 CRITICAL
Keenarch <2.0.1 - File Upload
CVSS 9.9
CVE-2025-68553 CRITICAL
Lendiz <2.0.1 - File Upload
CVSS 9.9
CVE-2025-14532 CRITICAL
DobryCMS <5.0 - RCE
CVSS 9.8
CVE-2025-69771 CRITICAL
asbplayer 1.13.0 - Code Injection
CVSS 9.6
CVE-2025-69403 CRITICAL
Bravis Addons <=1.1.9 - File Upload
CVSS 9.9
CVE-2025-68549 CRITICAL
Wiguard <2.0.1 - File Upload
CVSS 9.9
CVE-2025-13590 CRITICAL
Deployment - RCE via File Upload
CVSS 9.1
CVE-2025-12500 MEDIUM
Checkout Field Manager for WooCommerce <=7.8.1 - Unauthenticated Fi...
CVSS 5.3
CVE-2025-70151 HIGH
Scholars Tracking System 1.0 - Authenticated RCE
CVSS 8.8
CVE-2025-13689 HIGH
IBM DataStage on Cloud Pak - Command Injection
CVSS 8.8
CVE-2025-36183 LOW
IBM watsonx.data 2.2-2.2.1 - Code Injection
CVSS 3.8
CVE-2025-14014 CRITICAL
NTN Information Processing Services Computer Software Hardware Indu...
CVSS 9.8
CVE-2025-10465 HIGH
Birtech Sensaway <9.02.2026 - RCE
CVSS 8.8
CVE-2025-69906 HIGH
Monstra Cms - Unrestricted File Upload
CVSS 8.8
CVE-2025-70849 MEDIUM
Stefanprodan Podinfo < 6.9.0 - XSS
CVSS 6.1
CVE-2025-69981 CRITICAL
Frangoteam Fuxa - Unrestricted File Upload
CVSS 9.8
CVE-2025-65875 HIGH
FPDF <1.86 - RCE
CVSS 8.8
CVE-2025-61506 CRITICAL
MediaCrush <1.0.1 - RCE
CVSS 9.8
CVE-2025-66480 CRITICAL
Wildfire IM <1.4.3 - File Upload
CVSS 9.8
CVE-2025-57795 CRITICAL
Explorance Blue < 8.14.13 - Unrestricted File Upload
CVSS 9.9
CVE-2025-57794 CRITICAL
Explorance Blue < 8.14.9 - Unrestricted File Upload
CVSS 9.1
Details
Vulnerabilities 4,010
Exploit Likelihood Medium