Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-434 Clear
ID Title
CVE-2026-65640 Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
CVE-2026-67678 Unrestricted File Upload in CVE-2026-67678 (CVE-2026-67678)
vulnerability in CVE-2026-67678 (CVE-2026-67678). Successful exploitation can lead to full system takeover.
CVE-2026-50768 Unrestricted File Upload in CVE-2026-50768 (CVE-2026-50768)
vulnerability in CVE-2026-50768 (CVE-2026-50768). Successful exploitation can lead to full system takeover.
CVE-2026-16137 Path Traversal in path-traversal (CVE-2026-16137)
path traversal in path-traversal (CVE-2026-16137). Successful exploitation can lead to full system takeover.
CVE-2026-74845 Unrestricted File Upload in CVE-2026-74845 (CVE-2026-74845)
vulnerability in CVE-2026-74845 (CVE-2026-74845). Successful exploitation can lead to full system takeover.
CVE-2026-16098 Unrestricted File Upload in wordpress (CVE-2026-16098)
vulnerability in wordpress (CVE-2026-16098). Successful exploitation can lead to full system takeover.
CVE-2026-14498 Unrestricted File Upload in wordpress (CVE-2026-14498)
vulnerability in wordpress (CVE-2026-14498). Successful exploitation can lead to full system takeover.
CVE-2026-74767 Unrestricted File Upload in CVE-2026-74767 (CVE-2026-74767)
vulnerability in CVE-2026-74767 (CVE-2026-74767). Risk of unauthorized operations or information disclosure.
CVE-2026-18438 Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
CVE-2026-15965 Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
CVE-2026-19839 Vulnerability in CVE-2026-19839 (CVE-2026-19839)
vulnerability in CVE-2026-19839 (CVE-2026-19839). Risk of unauthorized operations or information disclosure.
CVE-2026-66271 Unrestricted File Upload in dell (CVE-2026-66271)
vulnerability in dell (CVE-2026-66271). Successful exploitation can lead to full system takeover.
CVE-2026-66270 Unrestricted File Upload in dell (CVE-2026-66270)
vulnerability in dell (CVE-2026-66270). Successful exploitation can lead to full system takeover.
CVE-2026-49827 Vulnerability in CVE-2026-49827 (CVE-2026-49827)
vulnerability in CVE-2026-49827 (CVE-2026-49827). Successful exploitation can lead to full system takeover.
CVE-2026-65939 Path Traversal in CVE-2026-65939 (CVE-2026-65939)
path traversal in CVE-2026-65939 (CVE-2026-65939). Successful exploitation can lead to full system takeover.
CVE-2026-18391 Unrestricted File Upload in wordpress (CVE-2026-18391)
vulnerability in wordpress (CVE-2026-18391). Successful exploitation can lead to full system takeover.
CVE-2026-15039 Unrestricted File Upload in wordpress (CVE-2026-15039)
vulnerability in wordpress (CVE-2026-15039). Successful exploitation can lead to full system takeover.
CVE-2026-55676 Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
CVE-2026-13457 Unrestricted File Upload in wordpress (CVE-2026-13457)
vulnerability in wordpress (CVE-2026-13457). Confidential information can be exposed externally.
CVE-2025-31114 Vulnerability in CVE-2025-31114 (CVE-2025-31114)
vulnerability in CVE-2025-31114 (CVE-2025-31114). Risk of unauthorized operations or information disclosure.
CVE-2026-72762 Unrestricted File Upload in CVE-2026-72762 (CVE-2026-72762)
vulnerability in CVE-2026-72762 (CVE-2026-72762). Risk of unauthorized operations or information disclosure.
CVE-2026-72557 Unrestricted File Upload in CVE-2026-72557 (CVE-2026-72557)
vulnerability in CVE-2026-72557 (CVE-2026-72557). Successful exploitation can lead to full system takeover.
CVE-2026-24330 Unrestricted File Upload in CVE-2026-24330 (CVE-2026-24330)
vulnerability in CVE-2026-24330 (CVE-2026-24330). Confidential information can be exposed externally.
CVE-2026-72592 Unrestricted File Upload in CVE-2026-72592 (CVE-2026-72592)
vulnerability in CVE-2026-72592 (CVE-2026-72592). Successful exploitation can lead to full system takeover.
CVE-2026-19089 Unrestricted File Upload in wordpress (CVE-2026-19089)
vulnerability in wordpress (CVE-2026-19089). Successful exploitation can lead to full system takeover.
CVE-2026-16985 Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
CVE-2026-19383 Vulnerability in CVE-2026-19383 (CVE-2026-19383)
vulnerability in CVE-2026-19383 (CVE-2026-19383). Risk of unauthorized operations or information disclosure.
CVE-2026-19210 Vulnerability in CVE-2026-19210 (CVE-2026-19210)
vulnerability in CVE-2026-19210 (CVE-2026-19210). Risk of unauthorized operations or information disclosure.
CVE-2022-4995 Unrestricted File Upload in CVE-2022-4995 (CVE-2022-4995)
vulnerability in CVE-2022-4995 (CVE-2022-4995). Successful exploitation can lead to full system takeover.
CVE-2026-70558 Unrestricted File Upload in CVE-2026-70558 (CVE-2026-70558)
vulnerability in CVE-2026-70558 (CVE-2026-70558). Successful exploitation can lead to full system takeover. Exploitable via `POST /download/uploadFromRsByLocal`.
CVE-2026-67688 Unrestricted File Upload in CVE-2026-67688 (CVE-2026-67688)
vulnerability in CVE-2026-67688 (CVE-2026-67688). Successful exploitation can lead to full system takeover.
CVE-2026-3418 Unrestricted File Upload in CVE-2026-3418 (CVE-2026-3418)
vulnerability in CVE-2026-3418 (CVE-2026-3418). Successful exploitation can lead to full system takeover.
CVE-2026-19065 Vulnerability in CVE-2026-19065 (CVE-2026-19065)
vulnerability in CVE-2026-19065 (CVE-2026-19065). Risk of unauthorized operations or information disclosure.
CVE-2026-71434 Unrestricted File Upload in statamic/cms (CVE-2026-71434)
vulnerability in statamic/cms (CVE-2026-71434). Risk of unauthorized operations or information disclosure. Exploitable via ``assets``. Mitigation: upgrade to `5.74.3` or later.
CVE-2026-66665 Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-18969 Vulnerability in CVE-2026-18969 (CVE-2026-18969)
vulnerability in CVE-2026-18969 (CVE-2026-18969). Risk of unauthorized operations or information disclosure.
CVE-2026-18927 Vulnerability in CVE-2026-18927 (CVE-2026-18927)
vulnerability in CVE-2026-18927 (CVE-2026-18927). Risk of unauthorized operations or information disclosure.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-54416 Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
CVE-2026-14553 Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
CVE-2026-65986 Cross-Site Scripting (XSS) in CVE-2026-65986 (CVE-2026-65986)
cross-site scripting in CVE-2026-65986 (CVE-2026-65986). Risk of unauthorized operations or information disclosure.
CVE-2026-18788 Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
CVE-2026-14175 Unrestricted File Upload in CVE-2026-14175 (CVE-2026-14175)
vulnerability in CVE-2026-14175 (CVE-2026-14175). Successful exploitation can lead to full system takeover.
CVE-2026-67243 Unrestricted File Upload in jvn (CVE-2026-67243)
vulnerability in jvn (CVE-2026-67243). Successful exploitation can lead to full system takeover.
CVE-2026-16548 Unrestricted File Upload in wordpress (CVE-2026-16548)
vulnerability in wordpress (CVE-2026-16548). Risk of unauthorized operations or information disclosure.
CVE-2026-16618 Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
CVE-2026-61524 Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
CVE-2026-39931 Unrestricted File Upload in sqli (CVE-2026-39931)
vulnerability in sqli (CVE-2026-39931). Successful exploitation can lead to full system takeover.
CVE-2026-16060 Unrestricted File Upload in wordpress (CVE-2026-16060)
vulnerability in wordpress (CVE-2026-16060). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →