CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,018 vulnerabilities with CWE-434
CVE-2022-32176 CRITICAL
Gin-vue-admin < 2.5.3b - Unrestricted File Upload
CVSS 9.0
CVE-2022-42029 HIGH
Chamilo - Unrestricted File Upload
CVSS 8.8
CVE-2022-42154 CRITICAL
74cmsse - Unrestricted File Upload
CVSS 9.8
CVE-2022-3549 MEDIUM
SourceCodester Simple Cold Storage Management System 1.0 - Unrestri...
CVSS 4.7
CVE-2022-32177 CRITICAL
Gin-vue-admin < 2.5.2 - Unrestricted File Upload
CVSS 9.0
CVE-2022-41539 HIGH
Wedding Planner v1.0 - RCE
CVSS 8.8
CVE-2022-41538 HIGH
Wedding Planner v1.0 - Code Injection
CVSS 8.8
CVE-2022-41534 HIGH
Online Diagnostic Lab Management System v1.0 - Code Injection
CVSS 7.2
CVE-2022-41533 HIGH
Online Diagnostic Lab Management System v1.0 - RCE
CVSS 7.2
CVE-2022-3458 MEDIUM
Oretnom23 Human Resource Management System - Unrestricted File Upload
CVSS 6.3
CVE-2022-41406 HIGH
Church Management System <1.0 - RCE
CVSS 7.2
CVE-2022-40921 HIGH
DedeCMS V5.7.99 - File Upload
CVSS 7.2
CVE-2022-40777 HIGH
Interspire Email Marketer < 6.5.0 - Unrestricted File Upload
CVSS 8.8
CVE-2022-42044 CRITICAL
Democritus D8s-asns - Unrestricted File Upload
CVSS 9.8
CVE-2022-42043 CRITICAL
Democritus D8s-xml - Unrestricted File Upload
CVSS 9.8
CVE-2022-42040 CRITICAL
Democritus D8s-algorithms - Unrestricted File Upload
CVSS 9.8
CVE-2022-42039 CRITICAL
Democritus D8s-lists - Unrestricted File Upload
CVSS 9.8
CVE-2022-42038 CRITICAL
Democritus D8s-ip-addresses - Unrestricted File Upload
CVSS 9.8
CVE-2022-42037 CRITICAL
Democritus D8s-asns - Unrestricted File Upload
CVSS 9.8
CVE-2022-42036 CRITICAL
Democritus D8s-urls - Unrestricted File Upload
CVSS 9.8
CVE-2022-41387 CRITICAL
d8s-pdfs 0.1.0 - Code Injection
CVSS 9.8
CVE-2022-41386 CRITICAL
d8s-utility <0.1.0 - Code Injection
CVSS 9.8
CVE-2022-41385 CRITICAL
d8s-html <0.1.0 - Code Injection
CVSS 9.8
CVE-2022-41384 CRITICAL
d8s-domains <0.1.0 - Code Injection
CVSS 9.8
CVE-2022-41383 CRITICAL
d8s-archives 0.1.0 - Code Injection
CVSS 9.8
Details
Vulnerabilities 4,018
Exploit Likelihood Medium