Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 45/87
5.4
CVE-2024-2406

A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index

5.4
CVE-2024-34906

An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a cr

5.4
CVE-2024-34909

An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploadin

5.4
CVE-2024-34913

An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code vi

5.4
CVE-2024-0757

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file e

5.4
CVE-2024-42054

Cervantes through 0.5-alpha accepts insecure file uploads.

5.4
CVE-2024-12042

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S

5.4
CVE-2024-10584

The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-Sit

5.3
CVE-2024-23946

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, t

5.3
CVE-2024-25994

An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload desti

5.3
CVE-2024-28890

Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerabil

5.3
CVE-2024-40555

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.

5.0
CVE-2024-1925

A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of t

4.9
CVE-2024-22060

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, hi

4.9
CVE-2024-5911

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write admin

4.9
CVE-2024-40553

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

4.8
CVE-2024-1932

Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout

4.8
CVE-2024-3112

The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowin

4.8
CVE-2024-47528

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach

4.7
CVE-2024-0185

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been rated as critical. This issue affec

4.7
CVE-2023-7212

A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the f

4.7
CVE-2024-1008

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected b

4.7
CVE-2024-1253

A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126

4.7
CVE-2024-1818

A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this iss

4.7
CVE-2024-1819

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affect

4.7
CVE-2024-1918

A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affect

4.7
CVE-2024-1921

A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown f

4.7
CVE-2024-2058

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been declared as critical. Affec

4.7
CVE-2024-2059

A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected

4.7
CVE-2024-2268

A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0. It has been classified as critical. Affected is a

4.7
CVE-2024-2394

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t

4.7
CVE-2024-2754

A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unk

4.7
CVE-2024-3117

A vulnerability classified as critical was found in YouDianCMS up to 9.5.12. This vulnerability affects unknown code of

4.7
CVE-2024-3444

A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an u

4.7
CVE-2024-3521

A vulnerability was found in Byzoro Smart S80 Management Platform up to 20240317. It has been rated as critical. Affecte

4.7
CVE-2024-4681

A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is

4.7
CVE-2024-5043

A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown function

4.7
CVE-2024-6647

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affect

4.7
CVE-2024-20296

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat

4.7
CVE-2024-7277

A vulnerability was found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this issue

4.7
CVE-2024-7705

A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the

4.7
CVE-2024-7706

A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function u

4.7
CVE-2024-7910

A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by thi

4.7
CVE-2024-7917

A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue

4.7
CVE-2024-8166

A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical. This vulnerability affects unknow

4.7
CVE-2024-9278

A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue

4.7
CVE-2024-9280

A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as c

4.7
CVE-2024-9815

A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vu

4.7
CVE-2024-9816

A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue i

4.7
CVE-2024-9855

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started