CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 46 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38884 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38883 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38882 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38881 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | ||
| CVE-2022-38296 | Cri | 0.64 | 9.8 | 0.04 | Sep 12, 2022 | Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. | ||
| CVE-2022-36557 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file. | ||
| CVE-2022-37181 | — | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2022 | 72crm 9.0 has an Arbitrary file upload vulnerability. | |
| CVE-2022-35150 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2022 | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. | ||
| CVE-2022-2180 | Cri | 0.64 | 9.8 | 0.02 | Aug 15, 2022 | The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution… | ||
| CVE-2022-35426 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2022 | UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. | ||
| CVE-2022-34613 | Cri | 0.64 | 9.8 | 0.02 | Aug 2, 2022 | Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-34496 | Cri | 0.64 | 9.8 | 0.01 | Jul 29, 2022 | Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature. | ||
| CVE-2022-28369 | Cri | 0.64 | 9.8 | 0.01 | Jul 14, 2022 | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation of the crtcrpc JSON listener (found at /lib/functions/wnc_jsonsh/crtcmode.sh) A remote attacker on the local network can provide a… | ||
| CVE-2022-30216 | Hig | 0.64 | 8.8 | 0.89 | Jul 12, 2022 | Windows Server Service Tampering Vulnerability | ||
| CVE-2021-29281 | Cri | 0.64 | 9.8 | 0.02 | Jul 7, 2022 | File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317. | ||
| CVE-2022-32413 | Cri | 0.64 | 9.8 | 0.02 | Jul 5, 2022 | An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file. | ||
| CVE-2022-31943 | Cri | 0.64 | 9.8 | 0.02 | Jul 1, 2022 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. | ||
| CVE-2021-38945 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2022 | IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238. | ||
| CVE-2021-40954 | Cri | 0.64 | 9.8 | 0.02 | Jun 23, 2022 | Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code. | ||
| CVE-2022-31374 | Cri | 0.64 | 9.8 | 0.02 | Jun 21, 2022 | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file. |
- risk 0.64cvss 9.8epss 0.01
The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.04
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
- risk 0.64cvss 9.8epss 0.01
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.
- risk 0.64cvss 9.8epss 0.01
72crm 9.0 has an Arbitrary file upload vulnerability.
- risk 0.64cvss 9.8epss 0.01
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
- risk 0.64cvss 9.8epss 0.02
The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution…
- risk 0.64cvss 9.8epss 0.01
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
- risk 0.64cvss 9.8epss 0.02
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.
- risk 0.64cvss 9.8epss 0.01
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
- risk 0.64cvss 9.8epss 0.01
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation of the crtcrpc JSON listener (found at /lib/functions/wnc_jsonsh/crtcmode.sh) A remote attacker on the local network can provide a…
- risk 0.64cvss 8.8epss 0.89
Windows Server Service Tampering Vulnerability
- risk 0.64cvss 9.8epss 0.02
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
- risk 0.64cvss 9.8epss 0.02
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
- risk 0.64cvss 9.8epss 0.02
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
- risk 0.64cvss 9.8epss 0.02
Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.