CWE-434
4,107 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CVEs (4,107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Flexdotnetcms Project 1Flexdotnetcms Jun 17, 2026 Nov 12, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the for...Show more |
In Sentrifugo 3.2, users can share an announcement under "Organization -> Announcements" tab. Also, in this page, users can upload attachments with the shared announcements. This "Upload Attachment" functionality is suff...Show more |
In Sentrifugo 3.2, users can upload an image under "Assets -> Add" tab. This "Upload Images" functionality is suffered from "Unrestricted File Upload" vulnerability so attacker can upload malicious files using this funct...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Nov 10, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload...Show more |
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jp...Show more |
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administr...Show more |
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlle...Show more |
1Horizontcms Project 1Horizontcms Jun 17, 2026 Nov 5, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then u...Show more |
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template compone...Show more |
IBM i2 iBase 8.9.13 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 184579. |
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically proces...Show more |
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction. |
1Car Rental Management System Project 1Car Rental Management System Jun 17, 2026 Oct 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be upl...Show more |
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server. |
1Cisco 3Adaptive Security Appliance Adaptive Security Appliance SoftwareFirepower Threat DefenseJun 17, 2026 Oct 21, 2020 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files t...Show more |
An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. It allows unauthenticated users to upload JavaScript (in a file) via the expenses claiming functionality. However, to view the file, authentication is req...Show more |
The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file mana...Show more |
1Rainbowfishsoftware 1Pacsone Server Jun 17, 2026 Sep 30, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control. |
Re:Desk 2.3 allows insecure file upload. |
1Seat Reservation System Project 1Seat Reservation System Jun 17, 2026 Sep 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Seat Reservation System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading PHP files. |