Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 22/87
7.5
CVE-2025-6206

The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is

7.5
CVE-2025-7438

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid

7.5
CVE-2025-47187

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and th

7.5
CVE-2025-5061

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati

7.5
CVE-2025-6207

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati

7.5
CVE-2025-53119

An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to

7.5
CVE-2025-45586

An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a

7.5
CVE-2025-9212

The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th

7.5
CVE-2025-12048

An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessm

7.5
CVE-2025-65844

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/im

7.5
CVE-2025-13646

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio

7.5
CVE-2020-36882

Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory

7.3
CVE-2025-0460

A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affect

7.3
CVE-2024-57407

An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrar

7.3
CVE-2025-1165

A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUp

7.3
CVE-2025-1355

A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulne

7.3
CVE-2025-1555

A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability aff

7.3
CVE-2025-1646

A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unkno

7.3
CVE-2025-2219

A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unkno

7.3
CVE-2025-2705

A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload

7.3
CVE-2025-3566

A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the

7.3
CVE-2025-4468

A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This iss

7.3
CVE-2025-4923

A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.

7.3
CVE-2025-5299

A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. Thi

7.3
CVE-2025-5840

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Th

7.3
CVE-2025-6161

A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected

7.3
CVE-2025-6843

A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an

7.3
CVE-2025-7114

A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri

7.3
CVE-2025-7470

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is a

7.3
CVE-2025-7538

A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects

7.3
CVE-2025-7547

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1

7.3
CVE-2025-7931

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i

7.3
CVE-2025-8255

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects s

7.3
CVE-2025-8798

A vulnerability was found in oitcode samarium up to 0.9.6. It has been classified as critical. Affected is an unknown fu

7.3
CVE-2025-26497

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Edito

7.3
CVE-2025-26498

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (establish-

7.3
CVE-2025-9475

A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unkn

7.3
CVE-2025-9476

A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some u

7.3
CVE-2025-9772

A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Perfor

7.3
CVE-2025-9775

A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.

7.3
CVE-2025-10116

A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admi

7.3
CVE-2025-10371

A security flaw has been discovered in eCharge Hardy Barth Salia PLCC up to 2.3.81. This issue affects some unknown proc

7.3
CVE-2025-10424

A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The a

7.3
CVE-2025-10425

A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The i

7.3
CVE-2025-10447

A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of t

7.3
CVE-2025-56295

code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by upload

7.3
CVE-2025-10600

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /r

7.3
CVE-2025-55912

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in

7.3
CVE-2025-11318

A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerabi

7.3
CVE-2025-11347

A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function mov

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started