Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,206 CVEs tagged with CWE-4341,480 Critical, 1,614 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2017-1000238

Published Nov 17, 2017

InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacke…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000194

Published Nov 17, 2017

October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4334

Published Oct 23, 2017

edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15580

Published Oct 23, 2017

osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2664

Published Oct 17, 2017

Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in X2Engine X2CRM before 4.0 allows remote…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2780

Published Oct 16, 2017

Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000119

Published Oct 5, 2017

October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6090

Published Oct 3, 2017

Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file wit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14958

Published Oct 2, 2017

lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8249

Published Sep 28, 2017

The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14704

Published Sep 26, 2017

Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14079

Published Sep 22, 2017

Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12929

Published Sep 21, 2017

Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Executi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9619

Published Sep 19, 2017

Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authen…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 4,101-4,125 of 4,206 CVEsPage 165 of 169