CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient i
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any autho
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
72crm 9.0 has an Arbitrary file upload vulnerability.
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the r
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to exe
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third pa
The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third pa
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload maliciou
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_co
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability wh
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to ar
Arbitrary file upload vulnerability in php uploader
The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t
The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a
The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t
The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t
The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted b
The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thi
The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by
The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to e
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac
A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated att
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started