VulnSea

CWE-434

CVEs classified under CWE-434, newest first.

232 CVEsRSS

CVE-2025-23171High· 7.2
1y ago

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed…

▾ TwilightEPSS 0.55%via NVD
CVE-2025-31324Critical· 10.0CISA KEVPoC
1y ago

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could signifi…

▾ Hadalsap · netweaverEPSS 99%via NVD
CVE-2024-50623Critical· 9.8CISA KEVPoC
1y ago

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

▾ Hadalcleo · harmonyEPSS 99%via NVD
CVE-2024-6127Critical· 9.8PoC
2y ago

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all crypt…

▾ AbyssalEPSS 10%via NVD
CVE-2024-29859Critical· 9.8
2y ago

In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

▾ Midnightmisp-project · mispEPSS 0.82%via NVD
CVE-2024-25674Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.184

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

▾ Midnightmisp-project · mispEPSS 0.78%via NVD
CVE-2023-27168Critical· 9.8PoC
2y ago

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

▾ Abyssalxpand-it · write-back_managerEPSS 1.3%via NVD
CVE-2023-0943Medium· 4.7PoC
3y ago

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler.…

▾ Twilightmayurik · best_pos_management_systemEPSS 2.3%via NVD
CVE-2022-2356High· 8.8
4y ago

The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.

▾ Twilightmediajedi · user_private_filesEPSS 0.98%via NVD
CVE-2022-32119High· 8.8PoC
4y ago

Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.

Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.php and the import staff excel function at 1finance_master.inc.php.

▾ Midnightarox · school_erp_proEPSS 2.0%via NVD
CVE-2022-32114High· 8.8PoC
4y ago

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file

An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XSS attacks via a crafted PDF file. NOTE: the project documentation suggests that a user with the Media Library "Create…

▾ Midnightstrapi · strapiEPSS 2.0%via NVD
CVE-2021-42675Critical· 9.8
4y ago

Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory

Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution.

▾ Midnightkreado · kreasferoEPSS 2.4%via NVD
CVE-2022-24581High· 7.5
4y ago

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password …

▾ Twilightaceware · aceweb_online_portalEPSS 0.96%via NVD
CVE-2022-24239Critical· 9.8
4y ago

ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.

ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.

▾ Midnightaceware · aceweb_online_portalEPSS 1.1%via NVD
CVE-2022-29351Critical· 9.8
4y ago

An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file

An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnera…

▾ Midnighttiddlywiki · tiddlywiki5EPSS 2.5%via NVD
CVE-2020-19228High· 7.2
4y ago

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

▾ Twilightbludit · bluditEPSS 1.2%via NVD
CVE-2022-29347Critical· 9.8
4y ago

An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

▾ Midnightweb@rchiv_project · web@rchivEPSS 3.3%via NVD
CVE-2022-28568Critical· 9.8
4y ago

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

▾ Midnightsimple_doctor's_appointment_system_project · simple_doctor's_appointment_systemEPSS 3.3%via NVD
CVE-2022-27262Critical· 9.8
4y ago

An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.

An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary code via a crafted file.

▾ Midnightsailsjs · skipperEPSS 2.1%via NVD
CVE-2022-27260Critical· 9.8
4y ago

An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.

An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbitrary code via a crafted SVG file.

▾ Midnightbuttercms · buttercmsEPSS 3.1%via NVD
CVE-2022-28397Critical· 9.8
4y ago

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file

An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file. NOTE: Vendor states as detailed in Ghost's security documentation, files can only be upl…

▾ Midnightghost · ghostEPSS 3.5%via NVD
CVE-2022-26607High· 7.2
4y ago

A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.

A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file.

▾ Twilightbaigo · baigo_cmsEPSS 2.2%via NVD
CVE-2022-26645Critical· 9.8
4y ago

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

▾ Midnightoretnom23 · banking_systemEPSS 2.5%via NVD
CVE-2021-40905High· 8.8PoC
4y ago

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation r…

▾ Midnightcheckmk · checkmkEPSS 3.0%via NVD
CVE-2022-23346High· 8.8
4y ago

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

▾ Twilightbigantsoft · bigant_serverEPSS 1.4%via NVD
CVE-2021-45834Critical· 9.8
4y ago

An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.

An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.

▾ Midnightopendocman · opendocmanEPSS 2.3%via NVD
CVE-2022-24254High· 8.8
4y ago

An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

▾ Twilightextensis · portfolioEPSS 2.6%via NVD
CVE-2022-24253High· 8.8
4y ago

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

▾ Twilightextensis · portfolioEPSS 1.3%via NVD
CVE-2022-24252High· 8.8
4y ago

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

▾ Twilightextensis · portfolioEPSS 2.3%via NVD
CVE-2022-24251High· 8.8
4y ago

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

▾ Twilightextensis · portfolioEPSS 1.3%via NVD
CWE-434 vulnerabilities (CVEs) — page 7 · VulnSea