CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A special
A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast
IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or si
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the f
A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code
A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing
PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket func
Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.
A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners C
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allow
An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitra
The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file up
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an
An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to
An arbitrary file upload vulnerability in Mindoc v2.1-beta.5 allows attackers to execute arbitrary commands via a crafte
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileg
When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox
Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the for
Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers
A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting
Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.
An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the sa
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file s
RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an exte
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en
The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX ac
A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of th
A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attac
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a f
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin pan
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file
Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Ty
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar f
The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows admin
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-s
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.
A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started