CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-46660 HIGH
Ge GE Proficy Historian 7.0 through 2023 - Unrestricted File Upload
CVSS 7.5
CVE-2022-42287 MEDIUM
Nvidia Bmc < 00.19.07 - Path Traversal
CVSS 6.0
CVE-2022-46610 HIGH
72crm v9 - RCE
CVSS 8.8
CVE-2022-44036 HIGH
b2evolution 7.2.5 - Command Injection
CVSS 7.2
CVE-2022-43436 HIGH
EasyTest - Code Injection
CVSS 8.8
CVE-2022-48194 HIGH
Tp-link Tl-wr902ac Firmware < 3.0.9.1 - Unrestricted File Upload
CVSS 8.8
CVE-2022-45427 HIGH
Dahuasecurity Dss Express - Unrestricted File Upload
CVSS 7.2
CVE-2022-4732 HIGH
Microweber < 1.3.1 - Unrestricted File Upload
CVSS 7.2
CVE-2022-45896 CRITICAL
Planetestream Planet Estream < 6.72.10.07 - Unrestricted File Upload
CVSS 9.8
CVE-2022-4665 HIGH
GitHub ampache/ampache <5.5.6 - Info Disclosure
CVSS 8.8
CVE-2022-46493 CRITICAL
nbnbk - File Upload
CVSS 9.8
CVE-2022-45415 HIGH
Mozilla Firefox < 107.0 - Unrestricted File Upload
CVSS 7.8
CVE-2022-34483 HIGH
Mozilla Firefox < 102.0 - Unrestricted File Upload
CVSS 8.8
CVE-2022-34482 HIGH
Mozilla Firefox < 102.0 - Unrestricted File Upload
CVSS 8.8
CVE-2022-0517 HIGH
Mozilla VPN <2.7.1 - RCE
CVSS 7.8
CVE-2022-46102 CRITICAL
AyaCMS 3.1.2 - File Upload
CVSS 9.8
CVE-2022-45966 CRITICAL
Classcms - Unrestricted File Upload
CVSS 9.8
CVE-2022-46020 CRITICAL
WBCE CMS v1.5.4 - Code Injection
CVSS 9.8
CVE-2022-46135 HIGH
AeroCms <0.0.1 - File Upload
CVSS 7.2
CVE-2022-45338 HIGH
Exactsoftware Exact Synergy - Unrestricted File Upload
CVSS 7.8
CVE-2022-4506 HIGH
Open-emr Openemr < 7.0.0.2 - Unrestricted File Upload
CVSS 8.8
CVE-2022-41267 CRITICAL
SAP Business Objects Platform - File Upload RCE
CVSS 9.9
CVE-2022-45275 HIGH
Dynamic Transaction Queuing System - Unrestricted File Upload
CVSS 7.2
CVE-2022-3912 HIGH
Wpeverest User Registration < 2.2.4.1 - Unrestricted File Upload
CVSS 7.5
CVE-2022-45968 HIGH
Alist < 3.5.1 - Unrestricted File Upload
CVSS 8.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium