CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions)
The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found
A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1
The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGE
The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege u
Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a
DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendte
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of th
Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an
Unrestricted upload of file with dangerous type for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within
HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, incl
The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected P
Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extens
The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If
An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of
An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFil
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnera
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated
An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of upl
An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file man
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and inc
marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default c
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to insecure use of the insta
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 an
An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoi
An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The u
A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated
An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote
An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in th
An unauthenticated arbitrary file upload vulnerability exists in LibrettoCMS version 1.1.7 (and possibly earlier) contai
The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability
WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerabilit
An unauthenticated arbitrary file upload vulnerability exists in Kordil EDMS v2.2.60rc3. The application exposes an uplo
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance vers
Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php.
Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The appli
MobileCartly version 1.0 contains an arbitrary file creation vulnerability in the savepage.php script. The application f
XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitra
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started