CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload wi
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.
The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.p
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows at
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary
Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker t
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returni
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/do
Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upl
Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the init
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder,
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.
Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a mal
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnera
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 a
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be
Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execu
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to executio
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution o
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious ph
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated
crater is vulnerable to Unrestricted Upload of File with Dangerous Type
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (th
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started