CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the contex
Unrestricted Upload of File with Dangerous Type vulnerability in WooRockets Corsa.This issue affects Corsa: from n/a thr
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to em
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded,
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploade
There is an arbitrary file upload vulnerability in the background of textpattern cms v4.8.8, which leads to the loss of
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML inte
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remo
SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to uplo
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Sli
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upl
An issue was discovered in the Open Document feature in Telindus Apsal 3.14.2022.235 b. An attacker may upload a crafted
An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated att
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary file
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before
Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_or
Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to uplo
Unrestricted Upload of File with Dangerous Type vulnerability in Mobatime web application (Documentary proof upload modu
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Vers
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates t
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in C
resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the files
act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github
A user could use the “Upload Resource” functionality to upload files to any location on the disk.
IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validat
File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted fil
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it g
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerabilit
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or d
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte
An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable c
An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to esc
An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code
An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploade
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the
Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not P
An unauthorized user could alter or write files with full control over the path and content of the file.
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Serv
CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file,
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the l
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive informat
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Arbitrary File Upload. The Ba
DataEase is an open source data visualization and analysis tool. Prior to version 1.18.11, DataEase has a vulnerability
There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started