CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
In CiviCRM before 5.21.3 and 5.22.x through 5.24.x before 5.24.3, users may be able to upload and execute a crafted PHAR
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /them
An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm
The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upl
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free
An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers t
Sitecore through 10.1, when Update Center is enabled, allows remote authenticated users to upload arbitrary files and ac
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote
IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary co
Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on th
The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check fo
An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary co
The web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in
SAP Business One, version - 10.0, allows an attacker with business authorization to upload any files (including script f
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati
firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vu
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file tr
Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can uplo
A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a r
S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Adm
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A r
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This
Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the
PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulner
An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can b
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.6, there is a vul
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, there is a vul
OpenMage is a community-driven alternative to Magento CE. In OpenMage before versions 19.4.10 and 20.0.5, an administrat
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started