CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an un
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affe
A vulnerability was found in codeprojects Online Driving School. It has been rated as critical. Affected by this issue i
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affect
A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to u
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the fun
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by this issue is some unknown
A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown func
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload
File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.
Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attac
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File w
wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.
Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.
The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allow
Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.
Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.
Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version
In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessibl
The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor direc
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attac
Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.
File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the Maia
A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this
A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vu
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic.
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected i
On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versi
Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extensio
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded w
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthe
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user control
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automa
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authent
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application.
Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request pa
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started