CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 22 of 92
- CVE-2022-42036CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.
- CVE-2022-41387CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
- CVE-2022-41386CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
- CVE-2022-41385CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
- CVE-2022-41384CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
- CVE-2022-41383CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- CVE-2022-41382CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- CVE-2022-41381CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- CVE-2022-41380CRITICALCVSS 9.8EG 9.82022-10-11
The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- CVE-2022-40721CRITICALCVSS 9.8EG 9.82022-10-03
Arbitrary file upload vulnerability in php uploader
- CVE-2021-45790CRITICALCVSS 9.8EG 9.82022-09-29
An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.
- CVE-2022-37346CRITICALCVSS 9.8EG 9.82022-09-27
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files ot…
- CVE-2022-40050CRITICALCVSS 9.8EG 9.82022-09-26
ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
- CVE-2022-40087CRITICALCVSS 9.8EG 9.82022-09-22
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2022-38916CRITICALCVSS 9.8EG 9.82022-09-20
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
- CVE-2022-40432CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.
- CVE-2022-40431CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- CVE-2022-38887CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.
- CVE-2022-38886CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- CVE-2022-38885CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- CVE-2022-38884CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- CVE-2022-38883CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- CVE-2022-38882CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- CVE-2022-38881CRITICALCVSS 9.8EG 9.82022-09-19
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
- CVE-2022-38296CRITICALCVSS 9.8EG 9.82022-09-12
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
- CVE-2020-21516CRITICALCVSS 9.8EG 9.82022-09-06
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
- CVE-2022-36557CRITICALCVSS 9.8EG 9.82022-08-29
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.
- CVE-2022-37159CRITICALCVSS 9.8EG 9.82022-08-25
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
- CVE-2022-37181CRITICALCVSS 9.8EG 9.82022-08-24
72crm 9.0 has an Arbitrary file upload vulnerability.
- CVE-2022-35150CRITICALCVSS 9.8EG 9.82022-08-22
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
- CVE-2022-2180CRITICALCVSS 9.8EG 9.82022-08-15
The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, lea…
- CVE-2022-35426CRITICALCVSS 9.8EG 9.82022-08-10
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
- CVE-2022-34613CRITICALCVSS 9.8EG 9.82022-08-02
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.
- CVE-2022-34496CRITICALCVSS 9.8EG 9.82022-07-29
Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
- CVE-2022-34115CRITICALCVSS 9.8EG 9.82022-07-22
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
- CVE-2021-36711CRITICALCVSS 9.8EG 9.82022-07-16
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
- CVE-2022-28369CRITICALCVSS 9.8EG 9.82022-07-14
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation of the crtcrpc JSON listener (found at /lib/functions/wnc_jsonsh/crtcmode.sh) A remote atta…
- CVE-2022-1952CRITICALCVSS 9.8EG 9.82022-07-11
The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessib…
- CVE-2021-29281CRITICALCVSS 9.8EG 9.82022-07-07
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.
- CVE-2022-32413CRITICALCVSS 9.8EG 9.82022-07-05
An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
- CVE-2022-31943CRITICALCVSS 9.8EG 9.82022-07-01
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
- CVE-2022-32994CRITICALCVSS 9.8EG 9.82022-06-27
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
- CVE-2022-1574CRITICALCVSS 9.8EG 9.82022-06-27
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
- CVE-2021-38945CRITICALCVSS 9.8EG 9.82022-06-24
IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by improper content validation. IBM X-Force ID: 211238.
- CVE-2021-40954CRITICALCVSS 9.8EG 9.82022-06-23
Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.
- CVE-2022-31374CRITICALCVSS 9.8EG 9.82022-06-21
An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.
- CVE-2022-2128CRITICALCVSS 9.8EG 9.82022-06-20
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
- CVE-2021-40940CRITICALCVSS 9.8EG 9.82022-06-15
Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
- CVE-2021-42675CRITICALCVSS 9.8EG 9.82022-06-14
Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.
- CVE-2022-32019CRITICALCVSS 9.8EG 9.82022-06-02
Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →