VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 110 of 216
  • CVE-2025-4648HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.00

    The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can inject JS script by altering the content of a SVG media, during the submit request. This issue affects web: from 24.10.0 before…

  • CVE-2024-41340HigFeb 27, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to…

  • CVE-2023-39307HigMar 26, 2024
    risk 0.55cvss 8.5epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

  • CVE-2023-25921HigFeb 29, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.

  • CVE-2023-50729HigJan 15, 2024
    risk 0.55cvss 8.4epss 0.01

    Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers to execute arbitrary code on the server. This vulnerability is more prevalent because Traccar is recommended to run web…

  • CVE-2023-47784HigDec 20, 2023
    risk 0.55cvss 8.4epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.

  • CVE-2023-26775HigApr 4, 2023
    risk 0.55cvss 7.8epss 0.49

    File Upload vulnerability found in Monitorr v.1.7.6 allows a remote attacker t oexecute arbitrary code via a crafted file upload to the assets/php/upload.php endpoint.

  • CVE-2023-24530HigFeb 14, 2023
    risk 0.55cvss 8.4epss 0.01

    SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely…

  • CVE-2022-0415HigMar 21, 2022
    risk 0.55cvss 8.8epss 0.65

    Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

  • CVE-2020-29032HigMar 5, 2021
    risk 0.55cvss 8.4epss 0.00

    Upload of Code Without Integrity Check vulnerability in firmware archive of Secomea GateManager allows authenticated attacker to execute malicious code on server. This issue affects: Secomea GateManager all versions prior to 9.4.621054022

  • CVE-2020-14209HigSep 2, 2020
    risk 0.55cvss 8.8epss 0.27

    Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be…

  • CVE-2018-15139HigAug 13, 2018
    risk 0.55cvss 8.8epss 0.19

    Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images…

  • CVE-2017-13156HigDec 6, 2017
    risk 0.55cvss 7.8epss 0.20

    An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.

  • CVE-2017-1000119HigOct 5, 2017
    risk 0.55cvss 7.2epss 0.61

    October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.

  • CVE-2024-44599HigDec 15, 2025
    risk 0.54cvss 8.3epss 0.00

    FNT Command 13.4.0 is vulnerable to Directory Traversal.

  • CVE-2025-48396HigNov 3, 2025
    risk 0.54cvss 8.3epss 0.00

    Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).

  • CVE-2025-55746CriAug 20, 2025
    risk 0.54cvss 9.3epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being…

  • CVE-2025-54071CriJul 21, 2025
    risk 0.54cvss epss 0.01

    RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta.3 and below, an authenticated arbitrary file write vulnerability exists in the /api/saves endpoint. This can lead to Remote Code…

  • CVE-2025-0520CriApr 29, 2025
    risk 0.54cvss epss 0.02

    An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

  • CVE-2023-39147HigAug 1, 2023
    risk 0.54cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.