CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_con
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows att
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the co
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the co
Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the c
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allow
Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in
Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_acti
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_w
An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execu
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbi
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the co
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the co
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_ac
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers t
File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers
An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbi
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUplo
Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/cl
An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing Sy
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of adm
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerabil
An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attacke
The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and ses
A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authe
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenti
A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unkn
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain ful
Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function
A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Af
A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System. It has been declared as critical. This v
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unkn
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unk
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability af
A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by t
A vulnerability has been found in SourceCodester Simple Online Book Store System and classified as critical. This vulner
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unkno
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is so
A vulnerability classified as critical was found in SourceCodester Gas Agency Management System. Affected by this vulner
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started