CWE-434
Medium likelihoodUnrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
4,227 vulnerabilities with CWE-434
CVE-2026-1126
MEDIUM
LWJ Flow - Unrestricted File Upload in SVG File Handler
CVSS 6.3
CVE-2026-1107
MEDIUM
EyouCMS <1.7.1/5.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-1061
MEDIUM
xiweicheng TMS <2.28.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-21625
HIGH
Stackideas Easydiscuss < 5.0.15 - Unrestricted File Upload
CVSS 8.8
CVE-2026-0496
MEDIUM
SAP Fiori App Intercompany Balance Reconciliation - File Upload
CVSS 6.6
CVE-2026-22799
HIGH
emlog < 2.6.1 - Authenticated Arbitrary File Upload via REST API Endpoint
CVSS 8.8
CVE-2026-22789
MEDIUM
Wem - Unrestricted File Upload
CVSS 5.4
CVE-2026-22786
HIGH
gin-vue-admin <= 2.8.7 - Path Traversal and Arbitrary File Write via Breakpoint Resume Upload
CVSS 7.2
CVE-2026-22783
CRITICAL
Iris <2.4.24 - Privilege Escalation
CVSS 9.6
CVE-2026-22241
HIGH
Openeclass < 4.1 - Unrestricted File Upload
CVSS 7.2
CVE-2026-21877
CRITICAL
n8n 0.123.0-1.121.2 - Authenticated Remote Code Execution via Git Node
CVSS 9.9
CVE-2026-0643
HIGH
projectworlds House Rental and Property Listing 1.0 - Unrestricted File Upload via Signup Image Parameter
CVSS 7.3
CVE-2026-0577
MEDIUM
Online Product Reservation System 1.0 - Unrestricted File Upload in prod.php
CVSS 6.3
CVE-2026-0566
MEDIUM
code-projects Content Management System 1.0 - Unrestricted File Upload via Image Argument
CVSS 4.7
CVE-2026-0547
MEDIUM
Online Course Registration < 3.1 - Unrestricted File Upload via Student Registration Page
CVSS 6.3
CVE-2025-24815
HIGH
Nokia MantaRay NM < 25R2-NM - Authenticated Unrestricted File Upload
CVSS 7.8
CVE-2025-69129
CRITICAL
WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site plugin <= 1.0.7 - Arbitrary File Upload vulnerability
CVSS 10.0
CVE-2025-60218
CRITICAL
WordPress PT Luxa Addons Plugin <= 1.2.2 - Arbitrary File Upload Vulnerability
CVSS 9.9
CVE-2025-59872
MEDIUM
HCL ZIE for Web 16.0 - Unrestricted File Upload
CVSS 4.3
CVE-2025-40808
MEDIUM
Siemens Siprotec 5 6MD84 (CP300) - Unrestricted Upload of File with Dangerous Type
CVSS 6.1
CVE-2025-65416
MEDIUM
docuFORM Managed Print Service Client 11.11c - Arbitrary File Upload
CVSS 6.3
CVE-2025-67886
MEDIUM
Bitrix24 through 25.100.300 - Remote Code Execution
CVSS 6.3
CVE-2025-36074
MEDIUM
Security vulnerability has been detected in IBM Security Verify Directory
CVSS 5.5
CVE-2025-14938
MEDIUM
Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload
CVSS 5.3
CVE-2025-59710
HIGH
BizTalk360 <11.5 - Malicious DLL Remote Code Execution
CVSS 8.8
Details
Vulnerabilities
4,227
Exploit Likelihood
Medium