CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2023-1484 MEDIUM
xzjie cms <1.0.3 - Unrestricted Upload
CVSS 6.3
CVE-2023-1479 MEDIUM
SourceCodester Simple Music Player 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2023-1442 MEDIUM
Meizhou Qingyunke QYKCMS 4.3.0 - Unrestricted Upload
CVSS 4.7
CVE-2023-1433 MEDIUM
SourceCodester Gadget Works Online Ordering System 1.0 - Unrestrict...
CVSS 4.7
CVE-2023-28337 HIGH
Netgear Rax30 Firmware - Unrestricted File Upload
CVSS 8.8
CVE-2023-1415 MEDIUM
Simple Art Gallery 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2023-27235 HIGH
Jizhicms <2.4.5 - RCE
CVSS 7.2
CVE-2023-27757 CRITICAL
Perfreeblog - Unrestricted File Upload
CVSS 9.8
CVE-2023-26262 HIGH
Sitecore XP/XM 10.3 - RCE
CVSS 7.2
CVE-2023-1392 MEDIUM
SourceCodester Online Pizza Ordering System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2023-1391 MEDIUM
SourceCodester Online Tours & Travels Management System 1.0 - Unres...
CVSS 4.7
CVE-2023-0477 HIGH
Cm-wp Auto Featured Image < 3.9.16 - Unrestricted File Upload
CVSS 8.8
CVE-2023-23328 HIGH
Avantfax - Unrestricted File Upload
CVSS 8.8
CVE-2023-1328 MEDIUM
115cms - Unrestricted File Upload
CVSS 4.7
CVE-2023-27164 MEDIUM
Halo <1.6.1 - RCE
CVSS 4.8
CVE-2023-1313 HIGH
Agentejo Cockpit < 2.4.0 - Unrestricted File Upload
CVSS 8.8
CVE-2023-1303 MEDIUM
Ucms - Unrestricted File Upload
CVSS 6.3
CVE-2023-22890 HIGH
Smartbear Zephyr Enterprise < 7.15 - Unrestricted File Upload
CVSS 7.5
CVE-2023-26949 CRITICAL
onekeyadmin <1.3.9 - RCE
CVSS 9.8
CVE-2023-1185 MEDIUM
Shopex Ecshop < 4.1.8 - Unrestricted File Upload
CVSS 4.7
CVE-2023-1184 MEDIUM
Shopex Ecshop < 4.1.8 - Unrestricted File Upload
CVSS 4.7
CVE-2023-25402 HIGH
Yf-exam - Unrestricted File Upload
CVSS 7.5
CVE-2023-20009 MEDIUM
Cisco Secure Email Gateway/SMA - Privilege Escalation
CVSS 6.5
CVE-2023-24045 MEDIUM
Dataiku DSS 11.2.1 - Info Disclosure
CVSS 6.5
CVE-2023-24249 HIGH
Laravel-Admin <1.8.19 - RCE
CVSS 7.2
Details
Vulnerabilities 4,018
Exploit Likelihood Medium