CWE-434 · 3 759 записей
Unrestricted Upload of File with Dangerous Type
CVE этого класса
3 759 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2018-15961Готовый эксплойт | Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploaadobe · coldfusion · CWE-434 | Критическая9,8 | KEV | 100,0 % | 25 сент. 2018 г. |
99Срочно | CVE-2025-31324Готовый эксплойт | Missing Authorization check in SAP NetWeaver (Visual Composer development server)sap · netweaver · CWE-434 | Критическая9,8 | KEV | 99,5 % | 24 апр. 2025 г. |
99Срочно | CVE-2024-50623Готовый эксплойт | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download thcleo · harmony · CWE-434 | Критическая9,8 | KEV | 98,6 % | 28 окт. 2024 г. |
99Срочно | CVE-2016-3088Готовый эксплойт | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTapache · activemq · CWE-434 | Критическая9,8 | KEV | 98,5 % | 1 июн. 2016 г. |
98Срочно | CVE-2020-25213Готовый эксплойт | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because filemanagerpro · file manager · CWE-434 | Критическая9,8 | KEV | 97,3 % | 9 сент. 2020 г. |
97Срочно | CVE-2026-48908Готовый эксплойт | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2ollyo · sp page builder · CWE-434 | Критическая10,0 | KEV | 88,5 % | 20 июн. 2026 г. |
96Срочно | CVE-2025-52691Готовый эксплойт | Upload Arbitrary Filessmartertools · smartermail · CWE-434 | Критическая10,0 | KEV | 85,7 % | 29 дек. 2025 г. |
92Срочно | CVE-2017-12617Готовый эксплойт | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Высокая8,1 | KEV | 100,0 % | 3 окт. 2017 г. |
92Срочно | CVE-2017-12615Готовый эксплойт | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Высокая8,1 | KEV | 99,6 % | 19 сент. 2017 г. |
92Срочно | CVE-2017-11357Готовый эксплойт | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackeprogress · telerik ui for asp.net ajax · CWE-434 | Критическая9,8 | KEV | 77,7 % | 23 авг. 2017 г. |
87Срочно | CVE-2020-8260Готовый эксплойт | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code eivanti · connect secure · CWE-434 | Высокая7,2 | KEV | 96,5 % | 28 окт. 2020 г. |
86Срочно | CVE-2021-31207Готовый эксплойт | Microsoft Exchange Server Security Feature Bypass Vulnerabilitymicrosoft · exchange server · CWE-434 | Средняя6,6 | KEV | 99,8 % | 11 мая 2021 г. |
79На этой неделе | CVE-2026-56290Готовый эксплойт | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0joomlack · page builder ck · CWE-434 | Критическая10,0 | KEV | 30,9 % | 29 июн. 2026 г. |
77На этой неделе | CVE-2021-27860Готовый эксплойт | Arbitrary file upload vulnerability in FatPipe softwarefatpipeinc · ipvpn firmware · CWE-434 | Высокая8,8 | KEV | 39,8 % | 8 дек. 2021 г. |
77На этой неделе | CVE-2021-26828Готовый эксплойт | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP fscadabr · scadabr · CWE-434 | Высокая8,8 | KEV | 39,4 % | 11 июн. 2021 г. |
76На этой неделе | CVE-2020-13671Готовый эксплойт | Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extendrupal · drupal · CWE-434 | Высокая8,8 | KEV | 35,4 % | 20 нояб. 2020 г. |
76На этой неделе | CVE-2026-48939Готовый эксплойт | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15joomlic · icagenda · CWE-434 | Критическая10,0 | KEV | 20,1 % | 20 июн. 2026 г. |
75На этой неделе | CVE-2019-8394Готовый эксплойт | Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customizatzohocorp · manageengine servicedesk plus · CWE-434 | Средняя6,5 | KEV | 63,3 % | 17 февр. 2019 г. |
75На этой неделе | CVE-2024-57968Готовый эксплойт | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessibleadvantive · veracore · CWE-434 | Высокая8,8 | KEV | 32,3 % | 3 февр. 2025 г. |
74На этой неделе | CVE-2026-56291Готовый эксплойт | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1balbooa · forms · CWE-434 | Критическая10,0 | KEV | 14,9 % | 9 июл. 2026 г. |
73На этой неделе | CVE-2018-4063Готовый эксплойт | An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.sierrawireless · aleos · CWE-434 | Высокая8,8 | KEV | 27,1 % | 6 мая 2019 г. |
68На этой неделе | CVE-2021-3378Готовый эксплойт | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFilefortilogger · fortilogger · CWE-434 | Критическая9,8 | — | 97,5 % | 1 февр. 2021 г. |
68На этой неделе | CVE-2018-9206Готовый эксплойт | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0jquery file upload project · jquery file upload · CWE-434 | Критическая9,8 | — | 97,3 % | 11 окт. 2018 г. |
68На этой неделе | CVE-2020-24186Готовый эксплойт | A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated ugvectors · wpdiscuz · CWE-434 | Критическая10,0 | — | 94,6 % | 24 авг. 2020 г. |
67На этой неделе | CVE-2024-8856Готовый эксплойт | Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Uploadrevmakx · backup and staging by wp time capsule · CWE-434 | Критическая9,8 | — | 94,1 % | 16 нояб. 2024 г. |
- CVE-2018-1596199Срочно
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion25 сент. 2018 г.
- CVE-2025-3132499Срочно
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sap · netweaver24 апр. 2025 г.
- CVE-2024-5062399Срочно
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download th
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %cleo · harmony28 окт. 2024 г.
- CVE-2016-308899Срочно
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · activemq1 июн. 2016 г.
- CVE-2020-2521398Срочно
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %filemanagerpro · file manager9 сент. 2020 г.
- CVE-2026-4890897Срочно
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 89 %ollyo · sp page builder20 июн. 2026 г.
- CVE-2025-5269196Срочно
Upload Arbitrary Files
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 86 %smartertools · smartermail29 дек. 2025 г.
- CVE-2017-1261792Срочно
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · tomcat3 окт. 2017 г.
- CVE-2017-1261592Срочно
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · tomcat19 сент. 2017 г.
- CVE-2017-1135792Срочно
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 78 %progress · telerik ui for asp.net ajax23 авг. 2017 г.
- CVE-2020-826087Срочно
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 96 %ivanti · connect secure28 окт. 2020 г.
- CVE-2021-3120786Срочно
Microsoft Exchange Server Security Feature Bypass Vulnerability
СредняяCVSS 6,6KEVГотовый эксплойтEPSS 100 %microsoft · exchange server11 мая 2021 г.
- CVE-2026-5629079На этой неделе
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 31 %joomlack · page builder ck29 июн. 2026 г.
- CVE-2021-2786077На этой неделе
Arbitrary file upload vulnerability in FatPipe software
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 40 %fatpipeinc · ipvpn firmware8 дек. 2021 г.
- CVE-2021-2682877На этой неделе
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP f
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 39 %scadabr · scadabr11 июн. 2021 г.
- CVE-2020-1367176На этой неделе
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 35 %drupal · drupal20 нояб. 2020 г.
- CVE-2026-4893976На этой неделе
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 20 %joomlic · icagenda20 июн. 2026 г.
- CVE-2019-839475На этой неделе
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customizat
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 63 %zohocorp · manageengine servicedesk plus17 февр. 2019 г.
- CVE-2024-5796875На этой неделе
Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 32 %advantive · veracore3 февр. 2025 г.
- CVE-2026-5629174На этой неделе
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 15 %balbooa · forms9 июл. 2026 г.
- CVE-2018-406373На этой неделе
An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 27 %sierrawireless · aleos6 мая 2019 г.
- CVE-2021-337868На этой неделе
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile
КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %fortilogger · fortilogger1 февр. 2021 г.
- CVE-2018-920668На этой неделе
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %jquery file upload project · jquery file upload11 окт. 2018 г.
- CVE-2020-2418668На этой неделе
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated u
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %gvectors · wpdiscuz24 авг. 2020 г.
- CVE-2024-885667На этой неделе
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
КритическаяCVSS 9,8Готовый эксплойтEPSS 94 %revmakx · backup and staging by wp time capsule16 нояб. 2024 г.