Skip to content
Noroxi

CWE-434 · 3,722 records

Unrestricted Upload of File with Dangerous Type

CVEs in this class

3,721 records

  • Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · coldfusionSep 25, 2018

  • Missing Authorization check in SAP NetWeaver (Visual Composer development server)

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    sap · netweaverApr 24, 2025

  • In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download th

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    cleo · harmonyOct 27, 2024

  • The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · activemqJun 1, 2016

  • The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    filemanagerpro · file managerSep 9, 2020

  • Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2

    CriticalCVSS 10.0KEVWeaponizedEPSS 89%

    ollyo · sp page builderJun 20, 2026

  • Upload Arbitrary Files

    CriticalCVSS 10.0KEVWeaponizedEPSS 86%

    smartertools · smartermailDec 28, 2025

  • When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · tomcatOct 3, 2017

  • When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · tomcatSep 19, 2017

  • Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke

    CriticalCVSS 9.8KEVWeaponizedEPSS 78%

    progress · telerik ui for asp.net ajaxAug 23, 2017

  • A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e

    HighCVSS 7.2KEVWeaponizedEPSS 96%

    ivanti · connect secureOct 28, 2020

  • Microsoft Exchange Server Security Feature Bypass Vulnerability

    MediumCVSS 6.6KEVWeaponizedEPSS 100%

    microsoft · exchange serverMay 11, 2021

  • CVE-2026-56290
    79This week

    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0

    CriticalCVSS 10.0KEVWeaponizedEPSS 31%

    joomlack · page builder ckJun 29, 2026

  • CVE-2021-27860
    77This week

    Arbitrary file upload vulnerability in FatPipe software

    HighCVSS 8.8KEVWeaponizedEPSS 40%

    fatpipeinc · ipvpn firmwareDec 8, 2021

  • CVE-2021-26828
    77This week

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP f

    HighCVSS 8.8KEVWeaponizedEPSS 39%

    scadabr · scadabrJun 11, 2021

  • CVE-2020-13671
    76This week

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten

    HighCVSS 8.8KEVWeaponizedEPSS 35%

    drupal · drupalNov 20, 2020

  • CVE-2026-48939
    76This week

    Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15

    CriticalCVSS 10.0KEVWeaponizedEPSS 20%

    joomlic · icagendaJun 20, 2026

  • CVE-2019-8394
    75This week

    Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customizat

    MediumCVSS 6.5KEVWeaponizedEPSS 63%

    zohocorp · manageengine servicedesk plusFeb 17, 2019

  • CVE-2024-57968
    75This week

    Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible

    HighCVSS 8.8KEVWeaponizedEPSS 32%

    advantive · veracoreFeb 3, 2025

  • CVE-2026-56291
    74This week

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1

    CriticalCVSS 10.0KEVWeaponizedEPSS 15%

    balbooa · formsJul 9, 2026

  • CVE-2018-4063
    73This week

    An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.

    HighCVSS 8.8KEVWeaponizedEPSS 27%

    sierrawireless · aleosMay 6, 2019

  • CVE-2021-3378
    68This week

    FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile

    CriticalCVSS 9.8WeaponizedEPSS 98%

    fortilogger · fortiloggerFeb 1, 2021

  • CVE-2018-9206
    68This week

    Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

    CriticalCVSS 9.8WeaponizedEPSS 97%

    jquery file upload project · jquery file uploadOct 11, 2018

  • CVE-2020-24186
    68This week

    A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated u

    CriticalCVSS 10.0WeaponizedEPSS 95%

    gvectors · wpdiscuzAug 24, 2020

  • CVE-2024-8856
    67This week

    Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload

    CriticalCVSS 9.8WeaponizedEPSS 94%

    revmakx · backup and staging by wp time capsuleNov 16, 2024

All vulnerability classes