VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 3 of 215
  • CVE-2018-4063HigKEVMay 6, 2019
    risk 0.71cvss 8.8epss 0.28

    An exploitable remote code execution vulnerability exists in the upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can…

  • CVE-2024-48760CriJan 14, 2025
    risk 0.70cvss 9.8epss 0.45

    An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

  • CVE-2024-42640CriOct 11, 2024
    risk 0.70cvss 9.8epss 0.43

    angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to…

  • CVE-2023-51409CriApr 12, 2024
    risk 0.70cvss 10.0epss 0.63

    Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.

  • CVE-2023-46263CriDec 19, 2023
    risk 0.70cvss 9.8epss 0.82

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.

  • CVE-2021-37926CriOct 7, 2021
    risk 0.70cvss 9.8epss 0.74

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37918CriOct 7, 2021
    risk 0.70cvss 9.8epss 0.74

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-36741HigKEVJul 29, 2021
    risk 0.70cvss 8.8epss 0.05

    An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the…

  • CVE-2021-27964CriMar 5, 2021
    risk 0.70cvss 9.8epss 0.48

    SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

  • CVE-2020-13671HigKEVNov 20, 2020
    risk 0.70cvss 8.8epss 0.04

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0…

  • CVE-2020-8260HigKEVOct 28, 2020
    risk 0.70cvss 7.2epss 0.96

    A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

  • CVE-2018-17440CriOct 8, 2018
    risk 0.70cvss 9.8epss 0.38

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP…

  • CVE-2018-6580CriFeb 2, 2018
    risk 0.70cvss 9.8epss 0.36

    Arbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component request.

  • CVE-2015-4455CriMay 23, 2017
    risk 0.70cvss 9.8epss 0.41

    Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct…

  • CVE-2025-34077CriJul 9, 2025
    risk 0.69cvss epss 0.10

    An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and manipulating the…

  • CVE-2025-34040CriJun 24, 2025
    risk 0.69cvss epss 0.14

    An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of…

  • CVE-2024-27747CriMar 1, 2024
    risk 0.69cvss 9.8epss 0.24

    File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.

  • CVE-2021-30118CriJul 9, 2021
    risk 0.69cvss 9.8epss 0.60

    An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated…

  • CVE-2019-7274CriJul 1, 2019
    risk 0.69cvss 9.8epss 0.29

    Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.

  • CVE-2019-7816CriMay 24, 2019
    risk 0.69cvss 9.8epss 0.68

    ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.