Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,207 CVEs tagged with CWE-4341,481 Critical, 1,614 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2017-14521

Published Jan 26, 2018

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1342

Published Jan 26, 2018

A Vulnerability exists on Admin Console where an attacker can upload files to the Admin Console server, and potentially execute them. This impacts NetIQ Access Manager versions 4.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5997

Published Jan 25, 2018

An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-4834

Published Jan 24, 2018

A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PXC00-E.D V5.10 (All versions <…

CVSS 9.8 · Critical

CVE-2017-18048

Published Jan 23, 2018

Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercas…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16594

Published Jan 23, 2018

This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16736

Published Jan 12, 2018

An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3814

Published Jan 1, 2018

Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg fi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16949

Published Dec 19, 2017

An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15876

Published Dec 19, 2017

Unrestricted File Upload vulnerability in GPWeb 8.4.61 allows remote authenticated users to upload any type of file, including a PHP shell.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17727

Published Dec 18, 2017

DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13156

Published Dec 6, 2017

An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2017-15673

Published Nov 28, 2017

The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15054

Published Nov 27, 2017

An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To ex…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16941

Published Nov 25, 2017

October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by downloading a theme ZIP archive f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2737

Published Nov 22, 2017

VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticate…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 4,076-4,100 of 4,207 CVEsPage 164 of 169