CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the
A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability aff
A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an
A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vul
A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the com
A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vu
A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo d
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer fi
Insufficient verification vulnerability exists in Broadcast Mail CGI (pmc.exe) included in A.K.I Software's PMailServer/
A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulne
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endp
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. A
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an a
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uplo
A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerabili
A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function
A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic.
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the
Alf.io is a free and open source event attendance management system. An administrator on the alf.io application is able
A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part
A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects a
A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerab
Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the ne
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 p
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a de
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /d
An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions p
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) fil
The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code.
common-user-management is a robust Spring Boot application featuring user management services designed to control user a
An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to
ZOO-Project is a C-based WPS (Web Processing Service) implementation. A path traversal vulnerability was discovered in Z
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote code execution vulnerability that could allow an
There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unv
An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious fi
Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin –
Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue a
Unrestricted Upload of File with Dangerous Type vulnerability in Bertha.Ai BERTHA AI. Your AI co-pilot for WordPress and
Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue af
Unrestricted Upload of File with Dangerous Type vulnerability in Pixelemu TerraClassifieds – Simple Classifieds Plugin.T
Unrestricted Upload of File with Dangerous Type vulnerability in IOSS WP MLM SOFTWARE PLUGIN.This issue affects WP MLM S
A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and
A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to u
Unrestricted upload of file with dangerous type vulnerability in create template function in EasyUse MailHunter Ultimate
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started