CWE-434
4,107 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trianglemicroworks 1Scada Data Gateway Jun 17, 2025 May 3, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations...Show more |
1Trianglemicroworks 1Scada Data Gateway Jun 17, 2025 May 3, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway...Show more |
1Netgear 1Prosafe Network Management System Feb 6, 2025 May 3, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETG...Show more |
1Netgear 1Prosafe Network Management System Feb 6, 2025 May 3, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 NETGEAR ProSAFE Network Management System MFileUploadController Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations...Show more |
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the aiovg_create_attachment_from_external_image_url function in all versions up to, and inc...Show more |
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation in the /wp-json/instawp-connect/v1/config REST API endpoint in all ve...Show more |
1Royal Elementor Addons 1Royal Elementor Addons Apr 8, 2026 May 2, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This m...Show more |
1Donbermoy 1Pisay Online E Learning System Sep 26, 2025 Apr 30, 2024 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulat...Show more |
ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to upload of malicious files. This could result in a Remote Code Execution. |
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. |
Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fields, resulting in webshell execution. |
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix...Show more |
1Themeisle 1Product Addons & Fields For Woocommerce Apr 8, 2026 Apr 26, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18....Show more |
Unauthenticated file upload allows remote code execution.
This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
|
1Code Projects 1Simple School Management System Apr 4, 2025 Apr 25, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file. |
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. |
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the...Show more |
1Unlimited Elements 1Unlimited Elements For Elementor Apr 28, 2026 Apr 24, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimite...Show more |
Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5. |
Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.5.11. |