Перейти к содержимому
Noroxi

CWE-434 · 3 759 записей

Unrestricted Upload of File with Dangerous Type

CVE этого класса

3 759 записей

  • CVE-2018-15961
    99Срочно

    Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    adobe · coldfusion25 сент. 2018 г.

  • CVE-2025-31324
    99Срочно

    Missing Authorization check in SAP NetWeaver (Visual Composer development server)

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    sap · netweaver24 апр. 2025 г.

  • CVE-2024-50623
    99Срочно

    In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download th

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    cleo · harmony28 окт. 2024 г.

  • CVE-2016-3088
    99Срочно

    The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    apache · activemq1 июн. 2016 г.

  • CVE-2020-25213
    98Срочно

    The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    filemanagerpro · file manager9 сент. 2020 г.

  • CVE-2026-48908
    97Срочно

    Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 89 %

    ollyo · sp page builder20 июн. 2026 г.

  • CVE-2025-52691
    96Срочно

    Upload Arbitrary Files

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 86 %

    smartertools · smartermail29 дек. 2025 г.

  • CVE-2017-12617
    92Срочно

    When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %

    apache · tomcat3 окт. 2017 г.

  • CVE-2017-12615
    92Срочно

    When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %

    apache · tomcat19 сент. 2017 г.

  • CVE-2017-11357
    92Срочно

    Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 78 %

    progress · telerik ui for asp.net ajax23 авг. 2017 г.

  • CVE-2020-8260
    87Срочно

    A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 96 %

    ivanti · connect secure28 окт. 2020 г.

  • CVE-2021-31207
    86Срочно

    Microsoft Exchange Server Security Feature Bypass Vulnerability

    СредняяCVSS 6,6KEVГотовый эксплойтEPSS 100 %

    microsoft · exchange server11 мая 2021 г.

  • CVE-2026-56290
    79На этой неделе

    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 31 %

    joomlack · page builder ck29 июн. 2026 г.

  • CVE-2021-27860
    77На этой неделе

    Arbitrary file upload vulnerability in FatPipe software

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 40 %

    fatpipeinc · ipvpn firmware8 дек. 2021 г.

  • CVE-2021-26828
    77На этой неделе

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP f

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 39 %

    scadabr · scadabr11 июн. 2021 г.

  • CVE-2020-13671
    76На этой неделе

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 35 %

    drupal · drupal20 нояб. 2020 г.

  • CVE-2026-48939
    76На этой неделе

    Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 20 %

    joomlic · icagenda20 июн. 2026 г.

  • CVE-2019-8394
    75На этой неделе

    Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customizat

    СредняяCVSS 6,5KEVГотовый эксплойтEPSS 63 %

    zohocorp · manageengine servicedesk plus17 февр. 2019 г.

  • CVE-2024-57968
    75На этой неделе

    Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 32 %

    advantive · veracore3 февр. 2025 г.

  • CVE-2026-56291
    74На этой неделе

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 15 %

    balbooa · forms9 июл. 2026 г.

  • CVE-2018-4063
    73На этой неделе

    An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 27 %

    sierrawireless · aleos6 мая 2019 г.

  • CVE-2021-3378
    68На этой неделе

    FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile

    КритическаяCVSS 9,8Готовый эксплойтEPSS 98 %

    fortilogger · fortilogger1 февр. 2021 г.

  • CVE-2018-9206
    68На этой неделе

    Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

    КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %

    jquery file upload project · jquery file upload11 окт. 2018 г.

  • CVE-2020-24186
    68На этой неделе

    A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated u

    КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %

    gvectors · wpdiscuz24 авг. 2020 г.

  • CVE-2024-8856
    67На этой неделе

    Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload

    КритическаяCVSS 9,8Готовый эксплойтEPSS 94 %

    revmakx · backup and staging by wp time capsule16 нояб. 2024 г.

Все классы уязвимостей