Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-434

MITRE ↗

Unrestricted Upload of File with Dangerous Type

1,470
CRITICAL
1,708
HIGH
980
MEDIUM
37
LOW
4,302 CVEs · Page 69/87
9.8
CVE-2021-20125

An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileSe

9.8
CVE-2021-42342

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passe

9.8
CVE-2021-41745

ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

9.8
CVE-2021-36547

A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attacker

9.8
CVE-2021-36548

A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=bl

9.8
CVE-2021-41643

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload fie

9.8
CVE-2021-41644

Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously craf

9.8
CVE-2021-41646

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously

9.8
CVE-2021-26740

Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.

9.8
CVE-2020-18261

An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitra

9.8
CVE-2021-42669

A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which all

9.8
CVE-2021-28023

Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious

9.8
CVE-2021-41833

Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.

9.8
CVE-2021-43617

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val

9.8
CVE-2021-44093

A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass t

9.8
CVE-2021-42099

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

9.8
CVE-2021-27860 KEV

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p9

9.8
CVE-2021-43117

fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.

9.8
CVE-2021-40883

A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.

9.8
CVE-2021-41560

OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUti

9.8
CVE-2021-44159

4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary fil

9.8
CVE-2021-44164

Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allo

9.8
CVE-2021-44031

An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksetting

9.6
CVE-2021-32630

Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before versio

9.3
CVE-2020-36167

An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before ho

9.1
CVE-2021-21014

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload res

9.1
CVE-2021-24220

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0,

9.1
CVE-2021-36040

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an imprope

9.1
CVE-2021-36042

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an imprope

9.1
CVE-2021-38484

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or

9.1
CVE-2021-38471

There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existi

8.8
CVE-2020-19364

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

8.8
CVE-2020-24549

openMAINT before 1.1-2.4.2 allows remote authenticated users to run arbitrary JSP code on the underlying web server.

8.8
CVE-2021-3164

ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permis

8.8
CVE-2021-22858

Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrar

8.8
CVE-2021-27513

The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files becau

8.8
CVE-2021-20659

SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecifi

8.8
CVE-2021-28379

web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow

8.8
CVE-2021-24160

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing ma

8.8
CVE-2021-29641

Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions incl

8.8
CVE-2021-24224

The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticate

8.8
CVE-2021-24253

The Classyfrieds WordPress plugin through 3.8 does not properly check the uploaded file when an authenticated user adds

8.8
CVE-2021-32094

U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to upload arbitrary files.

8.8
CVE-2020-26678

vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse th

8.8
CVE-2021-24311

The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitr

8.8
CVE-2021-29092

Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station bef

8.8
CVE-2020-36141

BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpe

8.8
CVE-2021-26828 KEV

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe

8.8
CVE-2021-34128

LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=p

8.8
CVE-2021-27489

ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious

Frequently Asked Questions

What is CWE-434?

CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-434?

There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.

How can I protect against CWE-434 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.

Detect CWE-434 Vulnerabilities

CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.

Get Started