CWE-434
4,378 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,378)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Istrong 1Mountain Flood Disaster Prevention Monitoring And Early Warning System Jun 17, 2026 Jul 11, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This issue affects some unknown processing of the file...Show more |
1Istrong 1Mountain Flood Disaster Prevention Monitoring And Early Warning System Jun 17, 2026 Jul 11, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230706. This vulnerability affects unknown code of the file /Duty/AjaxHandle/Wr...Show more |
1Istrong 1Mountain Flood Disaster Prevention Monitoring And Early Warning System Jun 17, 2026 Jul 11, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in Suncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System up to 20230704. It has been rated as critical. Affected by this issue is some unknown functionality of the fil...Show more |
1Websiteguide Project 1Websiteguide Jun 17, 2026 Jul 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload. |
1Online Art Gallery Project 1Online Art Gallery Jun 17, 2026 Jul 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability. |
File Upload vulnerability in Zimbra ZCS 8.8.15 allows an authenticated privileged user to execute arbitrary code and obtain sensitive information via the ClientUploader function. |
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. |
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload. |
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Jul 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13. |
1Smartweb Infotech Job Board Project 1Smartweb Infotech Job Board Jun 17, 2026 Jul 4, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulati...Show more |
A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unres...Show more |
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function. |
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function. |
Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3. |
WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands with the root privilege. |
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges. |
Chemex through 3.7.1 is vulnerable to arbitrary file upload. |
1Guantang Equipment Management System Project 1Guantang Equipment Management System Jun 17, 2026 Jun 28, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload. |
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. |