CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown func
A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/
A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an u
A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file
A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExten
A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown
A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability a
A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown f
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload function
The WP ULike Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation i
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem
ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a rem
IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be e
Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi
REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. Thi
Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro
TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backe
An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers t
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upl
A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to p
KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its fi
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with
HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server
HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and cr
Gradio is an open-source Python package that allows quick building of demos and web application for machine learning mod
ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration
Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an improper file type validation vulnerability in the OCR
A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unkno
A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or
October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authen
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) co
SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker p
The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privile
Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Us
A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the
A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects
A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnera
A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affec
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects th
A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability af
A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an un
A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affect
IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulne
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started