Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 27/87
6.3
CVE-2025-24489

An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to s

6.3
CVE-2025-27714

An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unaut

6.3
CVE-2025-9397

A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits

6.3
CVE-2025-9400

A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/ba

6.3
CVE-2025-9406

A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsAr

6.3
CVE-2025-9415

A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c

6.3
CVE-2025-9795

A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the

6.3
CVE-2025-9800

A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue

6.3
CVE-2025-9841

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown f

6.3
CVE-2025-9847

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of t

6.3
CVE-2025-9941

A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /regi

6.3
CVE-2025-9942

A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the fi

6.3
CVE-2025-10083

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some un

6.3
CVE-2025-10085

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects u

6.3
CVE-2025-10398

A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects un

6.3
CVE-2025-10427

A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function

6.3
CVE-2025-10428

A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknow

6.3
CVE-2025-10480

A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown func

6.3
CVE-2025-10615

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /adm

6.3
CVE-2025-10616

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file

6.3
CVE-2025-10669

A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component

6.3
CVE-2025-10741

A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown funct

6.3
CVE-2025-10755

A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component

6.3
CVE-2025-10763

A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by th

6.3
CVE-2025-11078

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown

6.3
CVE-2025-11320

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function up

6.3
CVE-2025-11351

A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown

6.3
CVE-2025-11352

A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown

6.3
CVE-2025-11353

A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of t

6.3
CVE-2025-11354

A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file

6.3
CVE-2025-11398

A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unkno

6.3
CVE-2025-11417

A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unk

6.3
CVE-2025-11426

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerabil

6.3
CVE-2025-11436

A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the

6.3
CVE-2025-11908

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the f

6.3
CVE-2025-12222

A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some u

6.3
CVE-2025-12223

A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/

6.3
CVE-2025-12268

A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown func

6.3
CVE-2025-12344

A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /

6.3
CVE-2025-12346

A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/m

6.3
CVE-2025-12347

A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsi

6.3
CVE-2025-12862

A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknow

6.3
CVE-2025-13061

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /ind

6.3
CVE-2025-13238

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functio

6.3
CVE-2025-13249

A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /Off

6.3
CVE-2025-13544

A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is

6.3
CVE-2025-13573

A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects u

6.3
CVE-2025-51736

File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.

6.3
CVE-2025-13815

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the

6.3
CVE-2025-13949

A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /serv

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started