CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerabi
NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. Th
BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers t
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t
NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. Th
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous T
Verint - CWE-434: Unrestricted Upload of File with Dangerous Type
The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missin
The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali
Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The
A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code throu
In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitr
The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation
The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u
The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u
The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application
The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to,
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows att
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attacke
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attack
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows a
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows at
The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload
The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading
Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an e
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension vali
An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitr
The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation
The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows a
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Pa
The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware fla
Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traver
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing f
File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to e
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Managem
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management
The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation an
6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regula
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner
Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/E
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started