Vulnerabilities (CVE)

Filtered by CWE-434
Total 1152 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-40797 1 Roxyfileman 1 Roxy Fileman 2025-05-01 N/A 9.8 CRITICAL
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)
CVE-2024-33120 1 Roothub 1 Roothub 2025-05-01 N/A 9.8 CRITICAL
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.
CVE-2024-25846 1 Simpleimportproduct Project 1 Simpleimportproduct 2025-04-30 N/A 9.1 CRITICAL
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
CVE-2024-37762 1 Machform 1 Machform 2025-04-30 N/A 9.9 CRITICAL
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
CVE-2024-34833 1 Oretnom23 1 Payroll Management System 2025-04-30 N/A 9.8 CRITICAL
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
CVE-2022-43234 1 Hoosk 1 Hoosk 2025-04-30 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43265 1 Canteen Management System Project 1 Canteen Management System 2025-04-30 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2020-23591 1 Optilinknetwork 2 Op-xt71000n, Op-xt71000n Firmware 2025-04-29 N/A 9.8 CRITICAL
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor.
CVE-2022-41705 1 Uatech 1 Badaso 2025-04-29 N/A 9.8 CRITICAL
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.
CVE-2022-44401 1 Online Tours \& Travels Management System Project 1 Online Tours \& Travels Management System 2025-04-29 N/A 9.8 CRITICAL
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
CVE-2025-46616 2025-04-29 N/A 9.9 CRITICAL
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
CVE-2025-46264 2025-04-29 N/A 9.9 CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Angelo Mandato PowerPress Podcasting allows Upload a Web Shell to a Web Server. This issue affects PowerPress Podcasting: from n/a through 11.12.5.
CVE-2024-48180 1 Classcms 1 Classcms 2025-04-28 N/A 9.8 CRITICAL
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.
CVE-2024-46101 1 Gdidees 1 Gdidees Cms 2025-04-28 N/A 9.8 CRITICAL
GDidees CMS <= v3.9.1 has a file upload vulnerability.
CVE-2024-40425 1 Sparkshop 1 Sparkshop 2025-04-28 N/A 9.8 CRITICAL
File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component.
CVE-2022-44400 1 Purchase Order Management System Project 1 Purchase Order Management System 2025-04-25 N/A 9.8 CRITICAL
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
CVE-2022-44354 1 Contec 2 Solarview Compact, Solarview Compact Firmware 2025-04-25 N/A 9.8 CRITICAL
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
CVE-2024-0864 1 Laragon 1 Laragon 2025-04-24 N/A 9.8 CRITICAL
Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin.
CVE-2025-29287 1 Mingsoft 1 Mcms 2025-04-24 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-24026 1 Xxyopen 1 Novel-plus 2025-04-24 N/A 9.8 CRITICAL
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.