CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web appl
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file uplo
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the
Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrar
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command inject
A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat ac
InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerabilit
InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vu
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type
File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitr
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to t
WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be sub
LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerabilit
greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/
Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layo
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v
SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious f
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'
The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due
There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation i
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may
The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and inc
A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the functi
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a
A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown
A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile
A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function
A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon o
A vulnerability was found in openBI up to 1.0.8. It has been classified as critical. Affected is the function index of t
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this v
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe
A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected
A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknow
A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an un
A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affe
A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affecte
A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as cr
A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated a
A vulnerability classified as critical has been found in itsourcecode Monbela Tourist Inn Online Reservation System up t
A vulnerability classified as critical was found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by
A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System
A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vu
A vulnerability has been found in wfh45678 Radar up to 1.0.8 and classified as critical. This vulnerability affects unkn
A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started