CWE-434
4,369 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,369)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Online Student Admission System Project 1Online Student Admission System Jun 17, 2026 Oct 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution. |
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is...Show more |
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system,...Show more |
Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user woul...Show more |
Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPE...Show more |
1Air Sender Project 1Air Sender Jun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file. |
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file...Show more |
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. |
There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files. |
1Catchplugins 1Catch Themes Demo Import Jun 17, 2026 Oct 21, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficie...Show more |
firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type |
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicious files to the server, which may allow an attacker, acting as an admin...Show more |
The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The file would be named usin...Show more |
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted enviro...Show more |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Oct 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Oct 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface. |
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerabilit...Show more |
PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code. |
PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does not filter all PHP extensions such as ".php, .php7, .phtml, .php5, ...". An attacker can upload a ma...Show more |
1Accesspressthemes 43Access Demo Importer Accesspress LiteAccesspress Mag+40 moreJun 17, 2026 Oct 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offlin...Show more |