Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 25/87
6.3
CVE-2025-0341

A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0

6.3
CVE-2025-0402

A vulnerability classified as critical was found in 1902756969 reggie 1.0. Affected by this vulnerability is the functio

6.3
CVE-2025-0463

A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified

6.3
CVE-2025-0702

A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. T

6.3
CVE-2025-1166

A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vuln

6.3
CVE-2025-1598

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affec

6.3
CVE-2025-1791

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the functio

6.3
CVE-2025-1818

A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unk

6.3
CVE-2025-1834

A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of

6.3
CVE-2025-1835

A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the fu

6.3
CVE-2025-1890

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function han

6.3
CVE-2025-2031

A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile o

6.3
CVE-2025-2035

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue

6.3
CVE-2025-2115

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affec

6.3
CVE-2025-2216

A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3.

6.3
CVE-2025-2350

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is

6.3
CVE-2025-29405

An arbitrary file upload vulnerability in the component /admin/template.php of emlog pro 2.5.0 and pro 2.5.* allows atta

6.3
CVE-2025-2606

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affec

6.3
CVE-2025-2607

A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected b

6.3
CVE-2025-2671

A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affe

6.3
CVE-2025-2687

A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown functio

6.3
CVE-2025-2702

A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function I

6.3
CVE-2025-2706

A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown func

6.3
CVE-2025-2952

A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknow

6.3
CVE-2025-2973

A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affect

6.3
CVE-2025-2978

A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionalit

6.3
CVE-2025-3040

A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by

6.3
CVE-2025-3041

A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an

6.3
CVE-2025-3042

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability a

6.3
CVE-2025-3244

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as cr

6.3
CVE-2025-3324

A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by thi

6.3
CVE-2025-3410

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code

6.3
CVE-2025-3558

A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown par

6.3
CVE-2025-3585

A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the fil

6.3
CVE-2025-3593

A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerab

6.3
CVE-2025-3764

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi

6.3
CVE-2025-3765

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen

6.3
CVE-2025-3783

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff

6.3
CVE-2025-3807

A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload

6.3
CVE-2025-3830

A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerabi

6.3
CVE-2025-3969

A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue

6.3
CVE-2025-4258

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the func

6.3
CVE-2025-4259

A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the func

6.3
CVE-2025-4291

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload.

6.3
CVE-2025-4305

A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the f

6.3
CVE-2025-4333

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critic

6.3
CVE-2025-4538

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the f

6.3
CVE-2025-4735

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this

6.3
CVE-2025-4768

A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects

6.3
CVE-2025-5108

A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Uplo

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started