VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 152 of 216
  • CVE-2025-57176MedSep 15, 2025
    risk 0.45cvss 6.5epss 0.00

    On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpiped service on TCP port 555 allows unauthenticated file uploads to any writable location on the device. File upload packets use weak encryption (metadata only)…

  • CVE-2024-7074MedJun 2, 2025
    risk 0.45cvss 6.8epss 0.12

    An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location on the server. By leveraging this…

  • CVE-2023-22726HigJan 20, 2023
    risk 0.45cvss 8.0epss 0.01

    act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may…

  • CVE-2021-35244MedDec 20, 2021
    risk 0.45cvss 6.8epss 0.06

    The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote…

  • CVE-2017-14841MedSep 28, 2017
    risk 0.45cvss 6.5epss 0.02

    Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.

  • CVE-2026-65939MedAug 12, 2026
    risk 0.44cvss 6.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

  • CVE-2025-66837MedJan 7, 2026
    risk 0.44cvss 6.8epss 0.00

    A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

  • CVE-2025-55810MedNov 13, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allows physical attackers to execute commands as root via script file with a specific name on a SD card.

  • CVE-2025-3125MedNov 5, 2025
    risk 0.44cvss 6.7epss 0.01

    An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the…

  • CVE-2025-1862MedSep 26, 2025
    risk 0.44cvss 6.7epss 0.01

    An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on…

  • CVE-2024-39752MedJul 10, 2025
    risk 0.44cvss 6.8epss 0.00

    IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type of file uploaded to Explore Content. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to…

  • CVE-2025-30173MedMay 22, 2025
    risk 0.44cvss 6.7epss 0.00

    File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2025-30169MedMay 22, 2025
    risk 0.44cvss 6.7epss 0.00

    File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2025-2748MedMar 24, 2025
    risk 0.44cvss 6.1epss 0.59

    The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.

  • CVE-2024-8725MedSep 26, 2024
    risk 0.44cvss 6.8epss 0.00

    Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated…

  • CVE-2024-34021MedAug 1, 2024
    risk 0.44cvss 6.8epss 0.00

    Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.

  • CVE-2024-38519HigJul 2, 2024
    risk 0.44cvss 7.8epss 0.00

    `yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could lead to arbitrary filenames being created in the download folder (and path traversal on…

  • CVE-2024-1532MedMar 27, 2024
    risk 0.44cvss 6.8epss 0.01

    A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.

  • CVE-2023-30968MedMar 12, 2024
    risk 0.44cvss 6.8epss 0.00

    One of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack.

  • CVE-2024-0939MedJan 26, 2024
    risk 0.44cvss 6.3epss 0.44

    A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can…