Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-434 Clear
ID Title
CVE-2026-16060 Unrestricted File Upload in wordpress (CVE-2026-16060)
vulnerability in wordpress (CVE-2026-16060). Successful exploitation can lead to full system takeover.
CVE-2026-12872 Unrestricted File Upload in wordpress (CVE-2026-12872)
vulnerability in wordpress (CVE-2026-12872). Successful exploitation can lead to full system takeover.
CVE-2026-13158 Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
CVE-2026-13157 Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
CVE-2026-53599 Unrestricted File Upload in redaxo/source (CVE-2026-53599)
vulnerability in redaxo/source (CVE-2026-53599). Successful exploitation can lead to full system takeover. Exploitable via ``shell.php.any.jpg``. Mitigation: upgrade to `5.21.1` or later.
CVE-2026-21662 Unrestricted File Upload in johnsoncontrols (CVE-2026-21662)
vulnerability in johnsoncontrols (CVE-2026-21662). Successful exploitation can lead to full system takeover.
CVE-2026-16236 Unrestricted File Upload in wordpress (CVE-2026-16236)
vulnerability in wordpress (CVE-2026-16236). Successful exploitation can lead to full system takeover.
CVE-2026-14483 Unrestricted File Upload in wordpress (CVE-2026-14483)
vulnerability in wordpress (CVE-2026-14483). Successful exploitation can lead to full system takeover.
CVE-2026-63223 Unrestricted File Upload in codeigniter4/framework (CVE-2026-63223)
vulnerability in codeigniter4/framework (CVE-2026-63223). Successful exploitation can lead to full system takeover. Exploitable via ``is_image``. Mitigation: upgrade to `4.7.4` or later.
CVE-2026-67206 Unrestricted File Upload in CVE-2026-67206 (CVE-2026-67206)
vulnerability in CVE-2026-67206 (CVE-2026-67206). Successful exploitation can lead to full system takeover.
CVE-2026-44103 Unrestricted File Upload in CVE-2026-44103 (CVE-2026-44103)
vulnerability in CVE-2026-44103 (CVE-2026-44103). Risk of unauthorized operations or information disclosure.
CVE-2026-44097 A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
CVE-2026-16610 Unrestricted File Upload in wordpress (CVE-2026-16610)
vulnerability in wordpress (CVE-2026-16610). Successful exploitation can lead to full system takeover.
CVE-2026-65885 Unrestricted File Upload in balbooa (CVE-2026-65885)
vulnerability in balbooa (CVE-2026-65885). Successful exploitation can lead to full system takeover.
CVE-2026-14270 Unrestricted File Upload in wordpress (CVE-2026-14270)
vulnerability in wordpress (CVE-2026-14270). Successful exploitation can lead to full system takeover.
CVE-2026-63228 Unrestricted File Upload in CVE-2026-63228 (CVE-2026-63228)
vulnerability in CVE-2026-63228 (CVE-2026-63228). Risk of unauthorized operations or information disclosure.
CVE-2026-63227 Unrestricted File Upload in CVE-2026-63227 (CVE-2026-63227)
vulnerability in CVE-2026-63227 (CVE-2026-63227). Successful exploitation can lead to full system takeover.
CVE-2026-12476 Unrestricted File Upload in wordpress (CVE-2026-12476)
vulnerability in wordpress (CVE-2026-12476). Successful exploitation can lead to full system takeover.
CVE-2026-13714 Unrestricted File Upload in wordpress (CVE-2026-13714)
vulnerability in wordpress (CVE-2026-13714). Successful exploitation can lead to full system takeover.
CVE-2026-10818 Unrestricted File Upload in wordpress (CVE-2026-10818)
vulnerability in wordpress (CVE-2026-10818). Successful exploitation can lead to full system takeover.
CVE-2026-24727 Unrestricted File Upload in CVE-2026-24727 (CVE-2026-24727)
vulnerability in CVE-2026-24727 (CVE-2026-24727). Risk of unauthorized operations or information disclosure.
CVE-2026-65461 Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
CVE-2026-65455 Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVE-2026-27064 Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-14282 Unrestricted File Upload in wordpress (CVE-2026-14282)
vulnerability in wordpress (CVE-2026-14282). Successful exploitation can lead to full system takeover.
CVE-2026-63048 Unrestricted File Upload in CVE-2026-63048 (CVE-2026-63048)
vulnerability in CVE-2026-63048 (CVE-2026-63048). Risk of unauthorized operations or information disclosure.
CVE-2026-58428 Vulnerability in code.gitea.io/gitea (CVE-2026-58428)
vulnerability in code.gitea.io/gitea (CVE-2026-58428). Data can be tampered with by attackers. Exploitable via `PATCH /api/v1/repos/bob/test-repo/releases/1/assets/1`. Mitigation: upgrade to `1.27.0` or later.
CVE-2026-16451 Vulnerability in CVE-2026-16451 (CVE-2026-16451)
vulnerability in CVE-2026-16451 (CVE-2026-16451). Risk of unauthorized operations or information disclosure.
CVE-2026-16447 Vulnerability in CVE-2026-16447 (CVE-2026-16447)
vulnerability in CVE-2026-16447 (CVE-2026-16447). Risk of unauthorized operations or information disclosure.
CVE-2026-16332 Vulnerability in CVE-2026-16332 (CVE-2026-16332)
vulnerability in CVE-2026-16332 (CVE-2026-16332). Risk of unauthorized operations or information disclosure.
CVE-2026-16331 Vulnerability in CVE-2026-16331 (CVE-2026-16331)
vulnerability in CVE-2026-16331 (CVE-2026-16331). Risk of unauthorized operations or information disclosure.
CVE-2026-16330 Vulnerability in CVE-2026-16330 (CVE-2026-16330)
vulnerability in CVE-2026-16330 (CVE-2026-16330). Risk of unauthorized operations or information disclosure.
CVE-2026-16329 Vulnerability in CVE-2026-16329 (CVE-2026-16329)
vulnerability in CVE-2026-16329 (CVE-2026-16329). Risk of unauthorized operations or information disclosure.
CVE-2026-16327 Vulnerability in CVE-2026-16327 (CVE-2026-16327)
vulnerability in CVE-2026-16327 (CVE-2026-16327). Risk of unauthorized operations or information disclosure.
CVE-2026-16324 Vulnerability in CVE-2026-16324 (CVE-2026-16324)
vulnerability in CVE-2026-16324 (CVE-2026-16324). Risk of unauthorized operations or information disclosure.
CVE-2026-53593 Unrestricted File Upload in laravel (CVE-2026-53593)
vulnerability in laravel (CVE-2026-53593). Successful exploitation can lead to full system takeover. Exploitable via `POST /uploads/upload`.
CVE-2026-61424 Unrestricted File Upload in CVE-2026-61424 (CVE-2026-61424)
vulnerability in CVE-2026-61424 (CVE-2026-61424). Risk of unauthorized operations or information disclosure.
CVE-2026-61900 Unrestricted File Upload in CVE-2026-61900 (CVE-2026-61900)
vulnerability in CVE-2026-61900 (CVE-2026-61900). Risk of unauthorized operations or information disclosure.
CVE-2026-60032 Unrestricted File Upload in CVE-2026-60032 (CVE-2026-60032)
vulnerability in CVE-2026-60032 (CVE-2026-60032). Risk of unauthorized operations or information disclosure.
CVE-2026-63429 Vulnerability in CVE-2026-63429 (CVE-2026-63429)
vulnerability in CVE-2026-63429 (CVE-2026-63429). Data can be tampered with by attackers. Exploitable via `POST /api/upload`.
CVE-2026-45797 Cross-Site Scripting (XSS) in express (CVE-2026-45797)
cross-site scripting in express (CVE-2026-45797). Risk of unauthorized operations or information disclosure.
CVE-2026-57311 Unrestricted File Upload in CVE-2026-57311 (CVE-2026-57311)
vulnerability in CVE-2026-57311 (CVE-2026-57311). Risk of unauthorized operations or information disclosure.
CVE-2026-16226 Vulnerability in CVE-2026-16226 (CVE-2026-16226)
vulnerability in CVE-2026-16226 (CVE-2026-16226). Risk of unauthorized operations or information disclosure.
CVE-2026-36669 Unrestricted File Upload in CVE-2026-36669 (CVE-2026-36669)
vulnerability in CVE-2026-36669 (CVE-2026-36669). Successful exploitation can lead to full system takeover.
CVE-2026-13352 Unrestricted File Upload in wordpress (CVE-2026-13352)
vulnerability in wordpress (CVE-2026-13352). Successful exploitation can lead to full system takeover.
CVE-2026-12684 Unrestricted File Upload in wordpress (CVE-2026-12684)
vulnerability in wordpress (CVE-2026-12684). Risk of unauthorized operations or information disclosure.
CVE-2026-50124 Unrestricted File Upload in CVE-2026-50124 (CVE-2026-50124)
vulnerability in CVE-2026-50124 (CVE-2026-50124). Risk of unauthorized operations or information disclosure.
CVE-2026-61457 Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
CVE-2026-11579 Unrestricted File Upload in wordpress (CVE-2026-11579)
vulnerability in wordpress (CVE-2026-11579). Risk of unauthorized operations or information disclosure.
CVE-2026-48356 Unrestricted File Upload in adobe (CVE-2026-48356)
vulnerability in adobe (CVE-2026-48356). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →