İçeriğe atla
Noroxi

CWE-434 · 3.722 kayıt

Unrestricted Upload of File with Dangerous Type

Bu sınıftaki CVE’ler

3.721 kayıt

  • Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file uploa

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · coldfusion25 Eyl 2018

  • Missing Authorization check in SAP NetWeaver (Visual Composer development server)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    sap · netweaver24 Nis 2025

  • In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download th

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    cleo · harmony27 Eki 2024

  • The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTT

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · activemq1 Haz 2016

  • The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    filemanagerpro · file manager9 Eyl 2020

  • Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %89

    ollyo · sp page builder20 Haz 2026

  • Upload Arbitrary Files

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %86

    smartertools · smartermail28 Ara 2025

  • When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100

    apache · tomcat3 Eki 2017

  • When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100

    apache · tomcat19 Eyl 2017

  • Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %78

    progress · telerik ui for asp.net ajax23 Ağu 2017

  • A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %96

    ivanti · connect secure28 Eki 2020

  • Microsoft Exchange Server Security Feature Bypass Vulnerability

    OrtaCVSS 6,6KEVSilahlaştırılmışEPSS %100

    microsoft · exchange server11 May 2021

  • CVE-2026-56290
    79Bu hafta

    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %31

    joomlack · page builder ck29 Haz 2026

  • CVE-2021-27860
    77Bu hafta

    Arbitrary file upload vulnerability in FatPipe software

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %40

    fatpipeinc · ipvpn firmware8 Ara 2021

  • CVE-2021-26828
    77Bu hafta

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP f

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %39

    scadabr · scadabr11 Haz 2021

  • CVE-2020-13671
    76Bu hafta

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect exten

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %35

    drupal · drupal20 Kas 2020

  • CVE-2026-48939
    76Bu hafta

    Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %20

    joomlic · icagenda20 Haz 2026

  • CVE-2019-8394
    75Bu hafta

    Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customizat

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %63

    zohocorp · manageengine servicedesk plus17 Şub 2019

  • CVE-2024-57968
    75Bu hafta

    Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones that are accessible

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %32

    advantive · veracore3 Şub 2025

  • CVE-2026-56291
    74Bu hafta

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %15

    balbooa · forms9 Tem 2026

  • CVE-2018-4063
    73Bu hafta

    An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %27

    sierrawireless · aleos6 May 2019

  • CVE-2021-3378
    68Bu hafta

    FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile

    KritikCVSS 9,8SilahlaştırılmışEPSS %98

    fortilogger · fortilogger1 Şub 2021

  • CVE-2018-9206
    68Bu hafta

    Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

    KritikCVSS 9,8SilahlaştırılmışEPSS %97

    jquery file upload project · jquery file upload11 Eki 2018

  • CVE-2020-24186
    68Bu hafta

    A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated u

    KritikCVSS 10,0SilahlaştırılmışEPSS %95

    gvectors · wpdiscuz24 Ağu 2020

  • CVE-2024-8856
    67Bu hafta

    Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload

    KritikCVSS 9,8SilahlaştırılmışEPSS %94

    revmakx · backup and staging by wp time capsule16 Kas 2024

Tüm zafiyet sınıfları