CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with D
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application allows users to
Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not P
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention
A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as criti
A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as proble
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. T
Brocade Fabric OS before Brocade Fabric OS v9.1.1c, v9.2.0 contains a vulnerability in the command line that could allow
An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write adminis
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue af
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload an
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to c
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. Thi
Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cros
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Rou
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS al
OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administrat
File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestri
A vulnerability, which was classified as problematic, was found in Maiwei Safety Production Control Platform 4.1. Affect
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md
Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected
A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file
A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. T
A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is so
A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of t
A vulnerability was found in Guizhou 115cms 4.2. It has been classified as problematic. Affected is an unknown function
A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management Syst
A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problemat
A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. It has been classified as problematic. This affects an unkn
A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vu
A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the f
A vulnerability was found in Zhong Bang CRMEB 4.6.0. It has been declared as critical. This vulnerability affects the fu
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the fi
A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this
A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been declared as critical. This vulnerability affect
A vulnerability has been found in flusity CMS and classified as critical. Affected by this vulnerability is the function
Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected
Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected
A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issu
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via th
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via th
A vulnerability was found in automad up to 1.10.9. It has been classified as problematic. This affects the function uplo
A vulnerability classified as critical was found in Campcodes Chic Beauty Salon 20230703. Affected by this vulnerability
A vulnerability was found in gopeak MasterLab up to 3.3.10. It has been declared as critical. Affected by this vulnerabi
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started