CWE-434
Medium likelihoodUnrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
4,225 vulnerabilities with CWE-434
CVE-2026-24014
CRITICAL
Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
CVSS 9.8
CVE-2026-14777
MEDIUM
SourceCodester Onlne Examination & Learning Management System announcements.php unrestricted upload
CVSS 6.3
CVE-2026-14776
MEDIUM
SourceCodester Onlne Examination & Learning Management System Filename Extension upload_files.php pathinfo unrestricted upload
CVSS 6.3
CVE-2026-14775
MEDIUM
SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload
CVSS 6.3
CVE-2026-14736
HIGH
Ruijie RG-UAC user_auth_commit.php unrestricted upload
CVSS 7.3
CVE-2026-14698
MEDIUM
SourceCodester Syllabus-Aligned Learning Management and Examination System upload_files.php unrestricted upload
CVSS 6.3
CVE-2026-5524
CRITICAL
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
CVSS 9.8
CVE-2026-27419
CRITICAL
WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-53909
MEDIUM
MyComplianceOffice MCO 25.3.3.1 - Authenticated Arbitrary File Upload
CVSS 6.5
CVE-2026-48283
CRITICAL
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
CVSS 10.0
CVE-2026-48276
CRITICAL
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
CVSS 10.0
CVE-2026-53691
HIGH
Remote Code Execution in Redeight CMS
CVE-2026-56290
CRITICAL
KEV
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
CVSS 9.8
CVE-2026-13165
HIGH
Remote Code Execution in SzafirHost
CVE-2026-13553
HIGH
itsourcecode Online Hotel Management System controller.php add unrestricted upload
CVSS 7.3
CVE-2026-13547
HIGH
Hanwang e-Face General Management Platform upload.do unrestricted upload
CVSS 7.3
CVE-2026-56414
HIGH
H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type
CVSS 7.2
CVE-2026-33560
HIGH
Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
CVSS 7.1
CVE-2026-57658
CRITICAL
WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability
CVSS 9.1
CVE-2026-56059
CRITICAL
WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-56058
CRITICAL
WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-56027
CRITICAL
WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-57700
CRITICAL
WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability
CVSS 10.0
CVE-2026-48946
MEDIUM
K2 for Joomla < 2.26 - Attachment PHP Upload Remote Code Execution
CVSS 6.3
CVE-2026-48945
MEDIUM
K2 for Joomla < 2.26 - Gallery Archive PHP Upload Remote Code Execution
CVSS 5.3
Details
Vulnerabilities
4,225
Exploit Likelihood
Medium