Перейти к содержимому
Noroxi

CWE-646 · 10 записей

Reliance on File Name or Extension of Externally-Supplied File

CVE этого класса

10 записей

  • CVE-2024-38432
    39Наблюдать

    Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    matrix-globalservices · tafnit30 июл. 2024 г.

  • CVE-2024-52052
    37Наблюдать

    Stream Target Remote Code Execution in Wowza Streaming Engine

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    wowza · streaming engine21 нояб. 2024 г.

  • CVE-2021-34639
    35Наблюдать

    WordPress Download Manager <= 3.1.24 Authenticated Arbitrary File Upload

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    w3eden · download manager5 авг. 2021 г.

  • CVE-2023-45599
    35Наблюдать

    A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web applicat

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ailux · imx65 мар. 2024 г.

  • CVE-2025-58449
    34Наблюдать

    Maho Vulnerable to Authenticated Remote Code Execution via File Upload

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    mahocommerce · maho8 сент. 2025 г.

  • CVE-2025-30662
    26Наблюдать

    Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    zoom · workplace virtual desktop infrastructure13 нояб. 2025 г.

  • GHSA-hw34-rqc5-h2gm
    22Наблюдать

    Duplicate Advisory: Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis

    СредняяCVSS 5,5Эксплойта нет

    PyPI · picklescan3 мар. 2025 г.

  • CVE-2025-1889
    21Наблюдать

    picklescan - Security scanning bypass via non-standard file extensions

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    mmaitre314 · picklescan3 мар. 2025 г.

  • CVE-2025-41720
    17Наблюдать

    Sauter: Arbitrary File Upload

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    sauter · modulo 6 devices modu680-as22 окт. 2025 г.

  • CVE-2026-20172
    17Наблюдать

    Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    cisco · cisco enterprise chat and email6 мая 2026 г.

Все классы уязвимостей