CWE-434 · 3,722 records
Unrestricted Upload of File with Dangerous Type
CVEs in this class
3,721 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2018-15961Weaponized | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploaadobe · coldfusion · CWE-434 | Critical9.8 | KEV | 100.0% | Sep 25, 2018 |
99Now | CVE-2025-31324Weaponized | Missing Authorization check in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-434 | Critical9.8 | KEV | 99.5% | Apr 24, 2025 |
99Now | CVE-2024-50623Weaponized | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download thcleo · harmony · CWE-434 | Critical9.8 | KEV | 98.6% | Oct 27, 2024 |
99Now | CVE-2016-3088Weaponized | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTapache · activemq · CWE-434 | Critical9.8 | KEV | 98.5% | Jun 1, 2016 |
98Now | CVE-2020-25213Weaponized | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because filemanagerpro · file manager · CWE-434 | Critical9.8 | KEV | 97.3% | Sep 9, 2020 |
97Now | CVE-2026-48908Weaponized | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2ollyo · sp page builder · CWE-434 | Critical10.0 | KEV | 88.5% | Jun 20, 2026 |
96Now | CVE-2025-52691Weaponized | Upload Arbitrary Filessmartertools · smartermail · CWE-434 | Critical10.0 | KEV | 85.7% | Dec 28, 2025 |
92Now | CVE-2017-12617Weaponized | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | High8.1 | KEV | 100.0% | Oct 3, 2017 |
92Now | CVE-2017-12615Weaponized | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | High8.1 | KEV | 99.6% | Sep 19, 2017 |
92Now | CVE-2017-11357Weaponized | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackeprogress · telerik ui for asp.net ajax · CWE-434 | Critical9.8 | KEV | 77.7% | Aug 23, 2017 |
87Now | CVE-2020-8260Weaponized | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code eivanti · connect secure · CWE-434 | High7.2 | KEV | 96.5% | Oct 28, 2020 |
86Now | CVE-2021-31207Weaponized | Microsoft Exchange Server Security Feature Bypass Vulnerabilitymicrosoft · exchange server · CWE-434 | Medium6.6 | KEV | 99.8% | May 11, 2021 |
79This week | CVE-2026-56290Weaponized | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0joomlack · page builder ck · CWE-434 | Critical10.0 | KEV | 30.9% | Jun 29, 2026 |
77This week | CVE-2021-27860Weaponized | Arbitrary file upload vulnerability in FatPipe softwarefatpipeinc · ipvpn firmware · CWE-434 | High8.8 | KEV | 39.8% | Dec 8, 2021 |
77This week | CVE-2021-26828Weaponized | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP fscadabr · scadabr · CWE-434 | High8.8 | KEV | 39.4% | Jun 11, 2021 |
76This week | CVE-2020-13671Weaponized | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extendrupal · drupal · CWE-434 | High8.8 | KEV | 35.4% | Nov 20, 2020 |
76This week | CVE-2026-48939Weaponized | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15joomlic · icagenda · CWE-434 | Critical10.0 | KEV | 20.1% | Jun 20, 2026 |
75This week | CVE-2019-8394Weaponized | Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customizatzohocorp · manageengine servicedesk plus · CWE-434 | Medium6.5 | KEV | 63.3% | Feb 17, 2019 |
75This week | CVE-2024-57968Weaponized | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessibleadvantive · veracore · CWE-434 | High8.8 | KEV | 32.3% | Feb 3, 2025 |
74This week | CVE-2026-56291Weaponized | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1balbooa · forms · CWE-434 | Critical10.0 | KEV | 14.9% | Jul 9, 2026 |
73This week | CVE-2018-4063Weaponized | An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.sierrawireless · aleos · CWE-434 | High8.8 | KEV | 27.1% | May 6, 2019 |
68This week | CVE-2021-3378Weaponized | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFilefortilogger · fortilogger · CWE-434 | Critical9.8 | — | 97.5% | Feb 1, 2021 |
68This week | CVE-2018-9206Weaponized | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0jquery file upload project · jquery file upload · CWE-434 | Critical9.8 | — | 97.3% | Oct 11, 2018 |
68This week | CVE-2020-24186Weaponized | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated ugvectors · wpdiscuz · CWE-434 | Critical10.0 | — | 94.6% | Aug 24, 2020 |
67This week | CVE-2024-8856Weaponized | Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Uploadrevmakx · backup and staging by wp time capsule · CWE-434 | Critical9.8 | — | 94.0% | Nov 16, 2024 |
- CVE-2018-1596199Now
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionSep 25, 2018
- CVE-2025-3132499Now
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sap · netweaverApr 24, 2025
- CVE-2024-5062399Now
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download th
CriticalCVSS 9.8KEVWeaponizedEPSS 99%cleo · harmonyOct 27, 2024
- CVE-2016-308899Now
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · activemqJun 1, 2016
- CVE-2020-2521398Now
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because
CriticalCVSS 9.8KEVWeaponizedEPSS 97%filemanagerpro · file managerSep 9, 2020
- CVE-2026-4890897Now
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
CriticalCVSS 10.0KEVWeaponizedEPSS 89%ollyo · sp page builderJun 20, 2026
- CVE-2025-5269196Now
Upload Arbitrary Files
CriticalCVSS 10.0KEVWeaponizedEPSS 86%smartertools · smartermailDec 28, 2025
- CVE-2017-1261792Now
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · tomcatOct 3, 2017
- CVE-2017-1261592Now
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · tomcatSep 19, 2017
- CVE-2017-1135792Now
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke
CriticalCVSS 9.8KEVWeaponizedEPSS 78%progress · telerik ui for asp.net ajaxAug 23, 2017
- CVE-2020-826087Now
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e
HighCVSS 7.2KEVWeaponizedEPSS 96%ivanti · connect secureOct 28, 2020
- CVE-2021-3120786Now
Microsoft Exchange Server Security Feature Bypass Vulnerability
MediumCVSS 6.6KEVWeaponizedEPSS 100%microsoft · exchange serverMay 11, 2021
- CVE-2026-5629079This week
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
CriticalCVSS 10.0KEVWeaponizedEPSS 31%joomlack · page builder ckJun 29, 2026
- CVE-2021-2786077This week
Arbitrary file upload vulnerability in FatPipe software
HighCVSS 8.8KEVWeaponizedEPSS 40%fatpipeinc · ipvpn firmwareDec 8, 2021
- CVE-2021-2682877This week
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP f
HighCVSS 8.8KEVWeaponizedEPSS 39%scadabr · scadabrJun 11, 2021
- CVE-2020-1367176This week
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten
HighCVSS 8.8KEVWeaponizedEPSS 35%drupal · drupalNov 20, 2020
- CVE-2026-4893976This week
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
CriticalCVSS 10.0KEVWeaponizedEPSS 20%joomlic · icagendaJun 20, 2026
- CVE-2019-839475This week
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customizat
MediumCVSS 6.5KEVWeaponizedEPSS 63%zohocorp · manageengine servicedesk plusFeb 17, 2019
- CVE-2024-5796875This week
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible
HighCVSS 8.8KEVWeaponizedEPSS 32%advantive · veracoreFeb 3, 2025
- CVE-2026-5629174This week
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CriticalCVSS 10.0KEVWeaponizedEPSS 15%balbooa · formsJul 9, 2026
- CVE-2018-406373This week
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.
HighCVSS 8.8KEVWeaponizedEPSS 27%sierrawireless · aleosMay 6, 2019
- CVE-2021-337868This week
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile
CriticalCVSS 9.8WeaponizedEPSS 98%fortilogger · fortiloggerFeb 1, 2021
- CVE-2018-920668This week
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
CriticalCVSS 9.8WeaponizedEPSS 97%jquery file upload project · jquery file uploadOct 11, 2018
- CVE-2020-2418668This week
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated u
CriticalCVSS 10.0WeaponizedEPSS 95%gvectors · wpdiscuzAug 24, 2020
- CVE-2024-885667This week
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8WeaponizedEPSS 94%revmakx · backup and staging by wp time capsuleNov 16, 2024