CWE-434
4,107 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 8.7.40, 9.5.25, 10.4.14, 11.1.1, due to the lack of ensuring file extensions belong to configured allowed mime-types, attackers ca...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by m...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the proces...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host onl...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host onl...Show more |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host onl...Show more |
1Webnus 1Modern Events Calendar Lite Jun 17, 2026 Mar 18, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' conte...Show more |
Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+)...Show more |
1Online Ordering System Project 1Online Ordering System Jun 17, 2026 Mar 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE). |
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix. |
2Myvestacp Vestacp2Myvesta Vesta Control PanelJun 17, 2026 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin. |
1Secomea 1Gatemanager 8250 Firmware Jun 17, 2026 Mar 5, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prio...Show more |
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for...Show more |
1Visualware 1Myconnection Server Jun 17, 2026 Feb 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This applicatio...Show more |
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into th...Show more |
1Contec 1Sv Cpt Mc310 Firmware Jun 17, 2026 Feb 24, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PHP script, an attacker may execute arbitrary code. |
1Iptime 9Nas I Firmware Nas Ii FirmwareNas Iie Firmware+6 moreJun 17, 2026 Feb 23, 2021 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36. |
1Yithemes 1Yith Woocommerce Gift Cards Jun 17, 2026 Feb 22, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context...Show more |
The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside." |
1Phpgurukul 1Car Rental Portal Jun 17, 2026 Feb 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php. |