VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 74 of 216
  • CVE-2021-38484CriOct 19, 2021
    risk 0.59cvss 9.1epss 0.03

    InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicious files to the server, which may allow an attacker, acting as an administrator, to upload malicious files. This could result in…

  • CVE-2021-36042CriSep 1, 2021
    risk 0.59cvss 9.1epss 0.02

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability in the API File Option Upload Extension. An attacker with Admin privileges can achieve unrestricted file upload which can…

  • CVE-2021-36040CriSep 1, 2021
    risk 0.59cvss 9.1epss 0.03

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An attacker with admin privileges can upload a specially crafted file to bypass file extension restrictions and could lead to…

  • CVE-2021-24220CriApr 12, 2021
    risk 0.59cvss 9.1epss 0.04

    Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme…

  • CVE-2021-27513HigFeb 22, 2021
    risk 0.59cvss 8.8epss 0.28

    The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."

  • CVE-2020-24195CriSep 9, 2020
    risk 0.59cvss 9.1epss 0.03

    An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.

  • CVE-2020-11943HigApr 29, 2020
    risk 0.59cvss 8.8epss 0.24

    An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.

  • CVE-2019-17058CriNov 18, 2019
    risk 0.59cvss 9.1epss 0.02

    Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by an Administrator who uploads a crafted upload.dat file.

  • CVE-2018-1969CriJan 14, 2019
    risk 0.59cvss 9.0epss 0.02

    IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750.

  • CVE-2018-3832CriAug 23, 2018
    risk 0.59cvss 9.0epss 0.02

    An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS binaries that could be modified to enable access to hidden resources which allow for uploading unsigned firmware images to the…

  • CVE-2018-12468CriAug 1, 2018
    risk 0.59cvss 9.1epss 0.02

    A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server. In certain circumstances this could result in remote code execution.

  • CVE-2017-7357CriApr 14, 2017
    risk 0.59cvss 9.1epss 0.03

    Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.

  • CVE-2026-21877CriJan 8, 2026
    risk 0.58cvss 9.9epss 0.05

    n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Cloud instances. This issue is…

  • CVE-2025-67288CriDec 22, 2025
    risk 0.58cvss 10.0epss 0.01

    An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system…

  • CVE-2025-9872HigSep 9, 2025
    risk 0.58cvss 8.8epss 0.14

    Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2014-125119HigJul 25, 2025
    risk 0.58cvss epss 0.01

    A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is…

  • CVE-2025-54441HigJul 23, 2025
    risk 0.58cvss 8.8epss 0.08

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

  • CVE-2025-54439HigJul 23, 2025
    risk 0.58cvss 8.8epss 0.07

    Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

  • CVE-2025-3914HigApr 26, 2025
    risk 0.58cvss 8.8epss 0.15

    The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with…

  • CVE-2024-10392CriOct 31, 2024
    risk 0.58cvss 9.8epss 0.15

    The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function in all versions up to, and including, 1.8.89. This makes it possible for unauthenticated attackers to upload…