CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index
An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a cr
An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploadin
An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code vi
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file e
Cervantes through 0.5-alpha accepts insecure file uploads.
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S
The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-Sit
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, t
An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload desti
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerabil
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.
A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of t
An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, hi
An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write admin
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.
Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout
The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowin
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been rated as critical. This issue affec
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the f
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected b
A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126
A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this iss
A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affect
A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affect
A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown f
A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been declared as critical. Affec
A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected
A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0. It has been classified as critical. Affected is a
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t
A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unk
A vulnerability classified as critical was found in YouDianCMS up to 9.5.12. This vulnerability affects unknown code of
A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an u
A vulnerability was found in Byzoro Smart S80 Management Platform up to 20240317. It has been rated as critical. Affecte
A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is
A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown function
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affect
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
A vulnerability was found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this issue
A vulnerability was found in Fujian mwcms 1.0.0. It has been declared as critical. Affected by this vulnerability is the
A vulnerability was found in Fujian mwcms 1.0.0. It has been rated as critical. Affected by this issue is the function u
A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by thi
A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue
A vulnerability has been found in Ruijie EG2000K 11.1(6)B2 and classified as critical. This vulnerability affects unknow
A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue
A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as c
A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vu
A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue i
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started