Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,206 CVEs tagged with CWE-4341,480 Critical, 1,614 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2025-69129

Published Jun 17, 2026

Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-60218

Published Jun 17, 2026

Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.

CVSS 9.9 · Critical

CVE-2025-59872

Published Jun 17, 2026

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52488

Published Jun 17, 2026

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

CVSS 9.9 · Critical

CVE-2026-40750

Published Jun 16, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store:…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-6933

Published Jun 16, 2026

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePlug…

CVSS 8.8 · High
evidence mentions
8
Buzz score
37.0

CVE-2026-40772

Published Jun 15, 2026

Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-39591

Published Jun 15, 2026

Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-39527

Published Jun 15, 2026

Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50873

Published Jun 15, 2026

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2018-25436

Published Jun 15, 2026

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exp…

CVSS 9.3 · Critical

CVE-2026-5482

Published Jun 15, 2026

Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Executi…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-34027

Published Jun 15, 2026

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint.…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-53724

Published Jun 12, 2026

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extensi…

CVSS 2.1 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-6211

Published Jun 12, 2026

Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This i…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-53787

Published Jun 12, 2026

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-46489

Published Jun 11, 2026

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrato…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-11839

Published Jun 11, 2026

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rot…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-7852

Published Jun 11, 2026

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9067

Published Jun 10, 2026

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-36722

Published Jun 9, 2026

An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted fil…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-40808

Published Jun 9, 2026

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-34031

Published Jun 9, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-su…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-33582

Published Jun 9, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive mem…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-11621

Published Jun 9, 2026

A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
24.4
Showing 101-125 of 4,206 CVEsPage 5 of 169