CWE-434
4,378 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,378)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cdwanjiang 1Flash Flood Disaster Monitoring And Warning System Jun 17, 2026 Jul 21, 2023 N/A· v4 3.7 LOW· v3 1.4 LOW· v2 A vulnerability classified as problematic has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This affects an unknown part of the file /Service/ImageStationDataService.asmx of the component...Show more |
1Cdwanjiang 1Flash Flood Disaster Monitoring And Warning System Jun 17, 2026 Jul 21, 2023 N/A· v4 9.8 CRITICAL· v3 5.2 MEDIUM· v2 A vulnerability was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Controller/Ajaxfileupload.a...Show more |
A vulnerability was found in EasyAdmin8 2.0.2.2. It has been classified as problematic. Affected is an unknown function of the file /admin/index/index.html#/admin/mall.goods/index.html of the component File Upload Module...Show more |
1Cdwanjiang 1Flash Flood Disaster Monitoring And Warning System Jun 17, 2026 Jul 20, 2023 N/A· v4 9.8 CRITICAL· v3 5.2 MEDIUM· v2 A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. T...Show more |
1Istrong 1Four Mountain Torrent Disaster Prevention, Control Monitoring And Early Warning System Jun 17, 2026 Jul 20, 2023 N/A· v4 8.8 HIGH· v3 5.2 MEDIUM· v2 A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of...Show more |
A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0. Affected by this issue is some unknown functionality of the file /user/profile of the component Profile Picture Handler...Show more |
1Infodoc 1Document On Line Submission And Approval System Jun 17, 2026 Jul 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attac...Show more |
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could r...Show more |
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aur...Show more |
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer. |
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote
code execution vulnerability that could allow an unauthenticated user to
upload a malicious payload and execute it.
|
1Evertz 33080ipx Firmware 7801fc Firmware7890ixg FirmwareJun 17, 2026 Jul 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files. |
1Veritas 1Infoscale Operations Manager Jun 17, 2026 Jul 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malic...Show more |
Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10. |
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
|
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file. |
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and includi...Show more |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5...Show more |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-...Show more |
1Simple Online Piggery Management System Project 1Simple Online Piggery Management System Jun 17, 2026 Jul 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php." |