CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 21 of 92
- CVE-2022-48008CRITICALCVSS 9.8EG 9.82023-01-27
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-40037CRITICALCVSS 9.8EG 9.82023-01-26
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.
- CVE-2022-0316CRITICALCVSS 9.8EG 9.82023-01-23
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, sou…
- CVE-2023-23607CRITICALCVSS 9.8EG 9.82023-01-20
erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/filesave.php allows for any file to uploa…
- CVE-2022-4047CRITICALCVSS 9.8EG 9.82022-12-26
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as …
- CVE-2022-45896CRITICALCVSS 9.8EG 9.82022-12-25
Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.
- CVE-2022-46493CRITICALCVSS 9.8EG 9.82022-12-22
Default version of nbnbk was discovered to contain an arbitrary file upload vulnerability via the component /api/User/download_img.
- CVE-2022-46102CRITICALCVSS 9.8EG 9.82022-12-22
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
- CVE-2022-45966CRITICALCVSS 9.8EG 9.82022-12-22
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
- CVE-2022-46020CRITICALCVSS 9.8EG 9.82022-12-20
WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
- CVE-2022-3982CRITICALCVSS 9.8EG 9.82022-12-12
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
- CVE-2022-3921CRITICALCVSS 9.8EG 9.82022-12-12
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
- CVE-2022-45359CRITICALCVSS 9.8EG 9.82022-12-06
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
- CVE-2022-36431CRITICALCVSS 9.8EG 9.82022-12-01
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
- CVE-2022-44354CRITICALCVSS 9.8EG 9.82022-11-29
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
- CVE-2022-44401CRITICALCVSS 9.8EG 9.82022-11-28
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
- CVE-2022-44400CRITICALCVSS 9.8EG 9.82022-11-28
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
- CVE-2022-45476CRITICALCVSS 9.8EG 9.82022-11-25
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.
- CVE-2022-41705CRITICALCVSS 9.8EG 9.82022-11-25
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.
- CVE-2020-23591CRITICALCVSS 9.8EG 9.82022-11-23
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm…
- CVE-2022-42698CRITICALCVSS 9.8EG 9.82022-11-18
Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.
- CVE-2022-43234CRITICALCVSS 9.8EG 9.82022-11-16
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-43265CRITICALCVSS 9.8EG 9.82022-11-15
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-43074CRITICALCVSS 9.8EG 9.82022-11-10
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-39036CRITICALCVSS 9.8EG 9.82022-11-10
The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary file and execute arbitrary code to manipulate system…
- CVE-2022-40797CRITICALCVSS 9.8EG 9.82022-11-09
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic w…
- CVE-2022-44054CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version o…
- CVE-2022-44053CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affecte…
- CVE-2022-44052CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected versi…
- CVE-2022-44051CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of…
- CVE-2022-44050CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-json package. The affected versi…
- CVE-2022-44049CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package. The affected versi…
- CVE-2022-44048CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version …
- CVE-2022-43305CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected ver…
- CVE-2022-43304CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version o…
- CVE-2022-43303CRITICALCVSS 9.8EG 9.82022-11-07
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version…
- CVE-2022-3575CRITICALCVSS 9.8EG 9.82022-11-02
Frauscher Sensortechnik GmbH FDS102 for FAdC R2 and FAdCi R2 v2.8.0 to v2.9.1 are vulnerable to malicious code upload without authentication by using the configuration upload function. This could lead to a complete compromise of the FDS102…
- CVE-2022-40471CRITICALCVSS 9.8EG 9.82022-10-31
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php
- CVE-2022-41711CRITICALCVSS 9.8EG 9.82022-10-25
Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.
- CVE-2022-36452CRITICALCVSS 9.8EG 9.82022-10-25
A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary code within the cont…
- CVE-2022-39305CRITICALCVSS 9.8EG 9.82022-10-24
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 contain a file upload ability. The affected code fails to validate fileMd5 and fileName para…
- CVE-2022-42154CRITICALCVSS 9.8EG 9.82022-10-17
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-42044CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.
- CVE-2022-42043CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.
- CVE-2022-42042CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.
- CVE-2022-42041CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-file-system package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.
- CVE-2022-42040CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.
- CVE-2022-42039CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.
- CVE-2022-42038CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.
- CVE-2022-42037CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →