← Back
CWE-434

4,369 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,369)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 14, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
1Erp Project
1Erp
Jun 17, 2026
Nov 11, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commo...Show more
A vulnerability was found in jerryhanjj ERP. It has been declared as critical. Affected by this vulnerability is the function uploadImages of the file application/controllers/basedata/inventory.php of the component Commodity Management. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-213451.Show less
1Etictelecom
1Remote Access Server Firmware
Jun 17, 2026
Nov 10, 2022
N/A· v4
10.0 CRITICAL· v3
N/A· v2
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensit...Show more
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise the affected device or computers with administrator level privileges connected to the affected device.Show less
1Ayacms Project
1Ayacms
Jun 17, 2026
Nov 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
1Flowring
1Agentflow
Jun 17, 2026
Nov 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary file and execute arbitrary code t...Show more
The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary file and execute arbitrary code to manipulate system or disrupt service.Show less
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP f...Show more
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via ip/youthappam/php_action/editFile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.Show less
1Roxyfileman
1Roxy Fileman
Jun 17, 2026
Nov 9, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter...Show more
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)Show less
1Online Tours And Travels Management System Project
1Online Tours And Travels Management System
Jun 17, 2026
Nov 7, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a craf...Show more
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component update_profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.Show less
1Democritus
1D8s Xml
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The...Show more
The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Networking
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents p...Show more
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Dates
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package....Show more
The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-timezones package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Stats
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The...Show more
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Networking
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-json package....Show more
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-json package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Python
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package....Show more
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-grammars package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Urls
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. Th...Show more
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Timer
Jun 17, 2026
Nov 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-dates package. The...Show more
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-dates package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Python
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms packag...Show more
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Timer
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The...Show more
The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1.0.Show less
1Democritus
1D8s Strings
Jun 17, 2026
Nov 7, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. T...Show more
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1.0.Show less
1Addify
1Role Based Pricing For Woocommerce
Jun 17, 2026
Nov 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upl...Show more
The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHPShow less