CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-45802 CRITICAL
Apache Streampark < 2.0.0 - Unrestricted File Upload
CVSS 9.8
CVE-2022-25277 HIGH
Drupal < 9.3.19 - Unrestricted File Upload
CVSS 7.2
CVE-2022-36769 HIGH
IBM Cloud Pak For Data - Command Injection
CVSS 7.2
CVE-2022-34128 CRITICAL
The Cartography <6.0.1 - RCE
CVSS 9.8
CVE-2022-47191 MEDIUM
Generex UPS CS141 <2.06 - Privilege Escalation
CVSS 4.3
CVE-2022-47190 CRITICAL
Generex UPS CS141 <2.06 - RCE
CVSS 10.0
CVE-2022-3682 CRITICAL
Hitachienergy Sdm600 < 1.3.0.1339 - Unrestricted File Upload
CVSS 9.9
CVE-2022-39983 CRITICAL
Instantdeveloper Rd3 - Unrestricted File Upload
CVSS 9.8
CVE-2022-41217 CRITICAL
Cloudflow - Unauthenticated File Upload
CVSS 9.8
CVE-2022-2883 HIGH
Octopus Deploy - DoS
CVSS 7.5
CVE-2022-45527 CRITICAL
Institutional Management Website - Unrestricted File Upload
CVSS 9.8
CVE-2022-48079 CRITICAL
Mengnai Aapanel Host System - Unrestricted File Upload
CVSS 9.8
CVE-2022-46604 HIGH
Tecrail Responsive FileManager <9.9.5 - Code Injection
CVSS 8.8
CVE-2022-42971 CRITICAL
Schneider-electric Apc Easy Ups Onlin... - Unrestricted File Upload
CVSS 9.8
CVE-2022-47769 CRITICAL
Serinf Fast Checkin - Unrestricted File Upload
CVSS 9.8
CVE-2022-47854 CRITICAL
I-librarian - Unrestricted File Upload
CVSS 9.8
CVE-2022-48006 CRITICAL
Taogogo Taocms - Unrestricted File Upload
CVSS 9.8
CVE-2022-43979 MEDIUM
Pandora FMS v764 - Path Traversal
CVSS 5.9
CVE-2022-48008 CRITICAL
Limesurvey - Unrestricted File Upload
CVSS 9.8
CVE-2022-47615 CRITICAL
Thimpress Learnpress < 4.2.0 - Unrestricted File Upload
CVSS 9.3
CVE-2022-47042 HIGH
MCMS <5.2.10 - File Write
CVSS 8.8
CVE-2022-40037 CRITICAL
Javaweb Blog - Unrestricted File Upload
CVSS 9.8
CVE-2022-40035 HIGH
Blog-ssm - Unrestricted File Upload
CVSS 8.8
CVE-2022-3478 MEDIUM
Gitlab < 15.4.6 - Unrestricted File Upload
CVSS 4.3
CVE-2022-47766 HIGH
Popojicms - Unrestricted File Upload
CVSS 8.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium