CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 27 of 92
- CVE-2021-26918CRITICALCVSS 9.8EG 9.82021-02-09
The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified other impact) because the uploader web ser…
- CVE-2021-3378CRITICALCVSS 9.8EG 9.82021-02-01
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.
- CVE-2020-20287CRITICALCVSS 9.8EG 9.82021-02-01
Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.
- CVE-2019-18643CRITICALCVSS 9.8EG 9.82021-01-07
Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods…
- CVE-2020-35797CRITICALCVSS 9.8EG 9.82020-12-30
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an unauthenticated attacker.
- CVE-2020-35665CRITICALCVSS 9.8EG 9.82020-12-23
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
- CVE-2020-25010CRITICALCVSS 9.8EG 9.82020-12-17
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request…
- CVE-2020-29597CRITICALCVSS 9.8EG 9.82020-12-07
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.
- CVE-2020-25537CRITICALCVSS 9.8EG 9.82020-11-30
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
- CVE-2020-28130CRITICALCVSS 9.8EG 9.82020-11-17
An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admi…
- CVE-2020-26553CRITICALCVSS 9.8EG 9.82020-11-17
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.
- CVE-2020-28140CRITICALCVSS 9.8EG 9.82020-11-17
SourceCodester Online Clothing Store 1.0 is affected by an arbitrary file upload via the image upload feature of Products.php.
- CVE-2020-23138CRITICALCVSS 9.8EG 9.82020-11-09
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type wit…
- CVE-2020-11486CRITICALCVSS 9.8EG 9.82020-10-29
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the prod…
- CVE-2020-27956CRITICALCVSS 9.8EG 9.82020-10-28
An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/asse…
- CVE-2020-25483CRITICALCVSS 9.8EG 9.82020-10-23
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
- CVE-2020-25763CRITICALCVSS 9.8EG 9.82020-09-30
Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files.
- CVE-2020-19672CRITICALCVSS 9.8EG 9.82020-09-30
Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, bypass the getimagesize function, upload php file, getshell.
- CVE-2020-12843CRITICALCVSS 9.8EG 9.82020-09-24
ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.
- CVE-2020-23828CRITICALCVSS 9.8EG 9.82020-09-15
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filte…
- CVE-2020-24199CRITICALCVSS 9.8EG 9.82020-09-09
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
- CVE-2020-24203CRITICALCVSS 9.8EG 9.82020-08-27
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.
- CVE-2020-24202CRITICALCVSS 9.8EG 9.82020-08-27
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.
- CVE-2020-14067CRITICALCVSS 9.8EG 9.82020-06-15
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/pack…
- CVE-2020-12800CRITICALCVSS 9.8EG 9.82020-06-08
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
- CVE-2018-21244CRITICALCVSS 9.8EG 9.82020-06-04
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfolio, aka FG-VD-18-029.
- CVE-2020-13442CRITICALCVSS 9.8EG 9.82020-05-25
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
- CVE-2020-12828CRITICALCVSS 9.8EG 9.82020-05-21
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides l…
- CVE-2020-11817CRITICALCVSS 9.8EG 9.82020-04-27
In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenan…
- CVE-2020-10569CRITICALCVSS 9.8EG 9.82020-04-21
SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining …
- CVE-2020-11815CRITICALCVSS 9.8EG 9.82020-04-16
In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance…
- CVE-2020-11811CRITICALCVSS 9.8EG 9.82020-04-16
In qdPM 9.1, an attacker can upload a malicious .php file to the server by exploiting the Add Profile Photo capability with a crafted content-type value. After that, the attacker can execute an arbitrary command on the server using this ma…
- CVE-2020-10507CRITICALCVSS 9.8EG 9.82020-04-15
The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted file upload (RCE) , that would allow attackers to gain access in the hosting machine.
- CVE-2020-11722CRITICALCVSS 9.8EG 9.82020-04-12
Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.
- CVE-2020-10621CRITICALCVSS 9.8EG 9.82020-04-09
Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
- CVE-2020-11598CRITICALCVSS 9.8EG 9.82020-04-06
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.
- CVE-2020-6008CRITICALCVSS 9.8EG 9.82020-03-31
LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution
- CVE-2020-10964CRITICALCVSS 9.8EG 9.82020-03-25
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.
- CVE-2020-10806CRITICALCVSS 9.8EG 9.82020-03-22
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP co…
- CVE-2020-9423CRITICALCVSS 9.8EG 9.82020-03-18
LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc provides a functionality to add documents. Those documents could then be used for mu…
- CVE-2016-6918CRITICALCVSS 9.8EG 9.82020-03-09
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
- CVE-2020-10225CRITICALCVSS 9.8EG 9.82020-03-08
An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP f…
- CVE-2020-10224CRITICALCVSS 9.8EG 9.82020-03-08
An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PH…
- CVE-2020-9380CRITICALCVSS 9.8EG 9.82020-03-05
IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.
- CVE-2016-11020CRITICALCVSS 9.8EG 9.82020-02-25
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
- CVE-2011-4908CRITICALCVSS 9.8EG 9.82020-02-12
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
- CVE-2011-4906CRITICALCVSS 9.8EG 9.82020-02-12
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
- CVE-2013-3684CRITICALCVSS 9.8EG 9.82020-02-11
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
- CVE-2013-2057CRITICALCVSS 9.8EG 9.82020-02-11
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
- CVE-2013-0803CRITICALCVSS 9.8EG 9.82020-02-11
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →