CWE-434
MITRE ↗Unrestricted Upload of File with Dangerous Type
SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Product
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary fil
An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain serv
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers S
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.
Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= UR
An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated ad
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result i
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm
The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .ph
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerabili
OpenVAS Manager v2.0.3 allows plugin remote code execution.
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before
An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerabilit
Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the applicatio
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .p
An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged
Umbraco Cloud 8.5.3 allows an authenticated file upload (and consequently Remote Code Execution) via the Install Package
An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 an
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute ar
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions wi
An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
Movable Type series (Movable Type 7 r.4606 (7.2.1) and earlier (Movable Type 7), Movable Type Advanced 7 r.4606 (7.2.1)
rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=file
The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks
documents_add.php in Kordil EDMS through 2.2.60rc3 allows Remote Command Execution because .php files can be uploaded to
ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose
An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the ser
A remote code execution vulnerability was identified in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to acces
Silverstripe CMS through 4.5 can be susceptible to script execution from malicious upload contents under allowed file ex
Frequently Asked Questions
What is CWE-434?
CWE-434 (Unrestricted Upload of File with Dangerous Type) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-434?
There are 5,180 CVE records associated with CWE-434 in our database. Of these, 1470 are critical severity, 1708 are high severity, and 980 are medium severity.
How can I protect against CWE-434 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-434 using AI-powered security agents.
Detect CWE-434 Vulnerabilities
CyberStrike's AI agents automatically detect unrestricted upload of file with dangerous type vulnerabilities across your infrastructure.
Get Started