CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-43085 HIGH
Codeastro Restaurant Pos System - Unrestricted File Upload
CVSS 7.2
CVE-2022-43083 HIGH
Vehicle Booking System - Unrestricted File Upload
CVSS 7.2
CVE-2022-39019 MEDIUM
M-Files Hubshare <3.3.11.3 - Info Disclosure
CVSS 6.3
CVE-2022-42925 CRITICAL
Formalms < 3.2.1 - Unrestricted File Upload
CVSS 9.9
CVE-2022-41681 CRITICAL
Forma LMS <3.1.0 - Privilege Escalation
CVSS 9.9
CVE-2022-40471 CRITICAL
Clinic's Patient Management System 1.0 - RCE
CVSS 9.8
CVE-2022-3771 MEDIUM
Easyiicms - Unrestricted File Upload
CVSS 6.3
CVE-2022-43283 MEDIUM
wasm2c <1.0.29 - Memory Corruption
CVSS 5.5
CVE-2022-43231 HIGH
Canteen Management System v1.0 - RCE
CVSS 7.2
CVE-2022-37426 MEDIUM
Opennebula < 6.4.2 - Unrestricted File Upload
CVSS 4.3
CVE-2022-43275 HIGH
Canteen Management System v1.0 - RCE
CVSS 7.2
CVE-2022-33859 HIGH
Eaton Foreseer EPMS <7.6 - File Upload
CVSS 8.1
CVE-2022-39978 HIGH
Online Pet Shop WE App - Unrestricted File Upload
CVSS 7.2
CVE-2022-39977 HIGH
Online Pet Shop WE App - Unrestricted File Upload
CVSS 7.2
CVE-2022-41711 CRITICAL
Badaso <2.6.0 - RCE
CVSS 9.8
CVE-2022-36452 CRITICAL
Mitel MiCollab <9.5.0.101 - RCE
CVSS 9.8
CVE-2022-39305 CRITICAL
Gin-vue-admin < 2.5.4b - Unrestricted File Upload
CVSS 9.8
CVE-2022-42189 HIGH
Emlog - Unrestricted File Upload
CVSS 7.2
CVE-2022-42201 HIGH
Simple Exam Reviewer Management System - Unrestricted File Upload
CVSS 7.2
CVE-2022-42198 HIGH
Simple Exam Reviewer Management System - Unrestricted File Upload
CVSS 8.8
CVE-2022-31366 HIGH
EVE-NG <2.0.3-112 - Code Injection
CVSS 7.2
CVE-2022-39301 HIGH
Sra-admin < 1.1.1 - Basic XSS
CVSS 8.2
CVE-2022-41537 HIGH
Online Tours & Travels Management System v1.0 - RCE
CVSS 7.2
CVE-2022-41504 HIGH
Billing System Project v1.0 - RCE
CVSS 7.2
CVE-2022-3552 HIGH
Boxbilling < 0.0.1 - Unrestricted Upload of File with Dangerous Type
CVSS 7.2
Details
Vulnerabilities 4,018
Exploit Likelihood Medium