← Back
CWE-434

4,378 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,378)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Istrong
1Mountain Flood Disaster Prevention Monitoring And Early Warning System
Jun 17, 2026
Jul 11, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file...Show more
A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file /Duty/AjaxHandle/UpLoadFloodPlanFile.ashx of the component UpLoadFloodPlanFile. The manipulation of the argument Filedata leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233579. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Istrong
1Mountain Flood Disaster Prevention Monitoring And Early Warning System
Jun 17, 2026
Jul 11, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Wr...Show more
A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Write/UploadFile.ashx of the component Duty Write-UploadFile. The manipulation of the argument Filedata leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-233578 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Istrong
1Mountain Flood Disaster Prevention Monitoring And Early Warning System
Jun 17, 2026
Jul 11, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the fil...Show more
A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Duty/AjaxHandle/UploadHandler.ashx of the component Duty Module. The manipulation of the argument Filedata leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-233576. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Websiteguide Project
1Websiteguide
Jun 17, 2026
Jul 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
1Online Art Gallery Project
1Online Art Gallery
Jun 17, 2026
Jul 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
1Zimbra
1Collaboration
Jun 17, 2026
Jul 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via the ClientUploader function.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jul 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
1Duxcms Project
1Duxcms
Jun 17, 2026
Jul 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
1Kiwitcms
1Kiwi Tcms
Jun 17, 2026
Jul 5, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files...Show more
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such files are accessed directly. The previous Nginx configuration was incorrect allowing certain browsers like Firefox to ignore the `Content-Type: text/plain` header on some occasions thus allowing potentially dangerous scripts to be executed. Additionally, file upload validators and parts of the HTML rendering code had been found to require additional sanitation and improvements. Version 12.5 fixes this vulnerability with updated Nginx content type configuration, improved file upload validation code to prevent more potentially dangerous uploads, and Sanitization of test plan names used in the `tree_view_html()` function.Show less
2Debian
Mozilla
4Debian Linux
FirefoxFirefox Esr+1 more
Jun 17, 2026
Jul 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
1Smartweb Infotech Job Board Project
1Smartweb Infotech Job Board
Jun 17, 2026
Jul 4, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulati...Show more
A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulation of the argument filename leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-232952. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Sanchitkmr
1Shopping Website
Jun 17, 2026
Jul 4, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unres...Show more
A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232951.Show less
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Jul 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
1Thedaylightstudio
1Fuel Cms
Jun 17, 2026
Jul 3, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
1Fossbilling
1Fossbilling
Jun 17, 2026
Jun 30, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.
1Wavlink
1Wl Wn531ax2 Firmware
Jun 17, 2026
Jun 30, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands with the root privilege.
1Sem Cms
1Semcms
Jun 17, 2026
Jun 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
1Chemex
1Chemex
Jun 17, 2026
Jun 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Chemex through 3.7.1 is vulnerable to arbitrary file upload.
1Guantang Equipment Management System Project
1Guantang Equipment Management System
Jun 17, 2026
Jun 28, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
1Tecrail
1Responsive Filemanager
Jun 17, 2026
Jun 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.