Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,206 CVEs tagged with CWE-4341,480 Critical, 1,614 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2020-35489

Published Dec 17, 2020

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characte…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-35133

Published Dec 16, 2020

irfanView 4.56 contains an error processing parsing files of type .pcx. Which leads to out-of-bounds writing at i_view32+0xdb60.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29607

Published Dec 16, 2020

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, whic…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26828

Published Dec 9, 2020

SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to en…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26826

Published Dec 9, 2020

Process Integration Monitoring of SAP NetWeaver AS JAVA, versions - 7.31, 7.40, 7.50, allows an attacker to upload any file (including script files) without proper file format val…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-23520

Published Dec 9, 2020

imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26255

Published Dec 8, 2020

Kirby is a CMS. In Kirby CMS (getkirby/cms) before version 3.4.5, and Kirby Panel before version 2.5.14 , an editor with full access to the Kirby Panel can upload a PHP .phar file…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29597

Published Dec 7, 2020

IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28939

Published Dec 3, 2020

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to u…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29441

Published Nov 30, 2020

An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may c…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25537

Published Nov 30, 2020

File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13671

Published Nov 20, 2020

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type…

CVSS 8.8 · High
evidence mentions
8
Buzz score
60.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-7569

Published Nov 19, 2020

A CWE-434 Unrestricted Upload of File with Dangerous Type vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote us…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-25406

Published Nov 18, 2020

app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26553

Published Nov 17, 2020

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28136

Published Nov 17, 2020

An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable pag…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28693

Published Nov 16, 2020

An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the P…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28692

Published Nov 16, 2020

In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13774

Published Nov 12, 2020

An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by upload…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,476-3,500 of 4,206 CVEsPage 140 of 169