Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-434 Clear
ID Title
CVE-2024-44598 FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
CVE-2018-4063 KEV [KEV] Unrestricted File Upload in Sierra wireless sierra-wireless (CVE-2018-4063)
vulnerability in Sierra wireless sierra-wireless (CVE-2018-4063). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-56704 Unrestricted File Upload in lepton-cms (CVE-2025-56704)
vulnerability in lepton-cms (CVE-2025-56704). Successful exploitation can lead to full system takeover.
CVE-2021-26828 KEV [KEV] Unrestricted File Upload in Openplc scadabr (CVE-2021-26828)
vulnerability in Openplc scadabr (CVE-2021-26828). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-0645 Unrestricted File Upload in CVE-2025-0645 (CVE-2025-0645)
vulnerability in CVE-2025-0645 (CVE-2025-0645). Successful exploitation can lead to full system takeover.
CVE-2025-34336 Unrestricted File Upload in CVE-2025-34336 (CVE-2025-34336)
vulnerability in CVE-2025-34336 (CVE-2025-34336). Risk of unauthorized operations or information disclosure.
CVE-2025-63748 Unrestricted File Upload in testmanagement (CVE-2025-63748)
vulnerability in testmanagement (CVE-2025-63748). Successful exploitation can lead to full system takeover.
CVE-2025-60731 PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
CVE-2025-60735 PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
CVE-2025-56218 Unrestricted File Upload in ascertia (CVE-2025-56218)
vulnerability in ascertia (CVE-2025-56218). Successful exploitation can lead to full system takeover.
CVE-2025-9846 Unrestricted File Upload in csharp (CVE-2025-9846)
vulnerability in csharp (CVE-2025-9846). Successful exploitation can lead to full system takeover.
CVE-2025-56295 Unrestricted File Upload in carmelo (CVE-2025-56295)
vulnerability in carmelo (CVE-2025-56295). Confidential information can be exposed externally.
CVE-2025-55835 Unrestricted File Upload in sueamcms-project (CVE-2025-55835)
vulnerability in sueamcms-project (CVE-2025-55835). Successful exploitation can lead to full system takeover.
CVE-2025-8889 Unrestricted File Upload in wordpress (CVE-2025-8889)
vulnerability in wordpress (CVE-2025-8889). Risk of unauthorized operations or information disclosure.
CVE-2025-34163 Unrestricted File Upload in CVE-2025-34163 (CVE-2025-34163)
vulnerability in CVE-2025-34163 (CVE-2025-34163). Risk of unauthorized operations or information disclosure.
CVE-2025-51056 Unrestricted File Upload in vedo-suite-project (CVE-2025-51056)
vulnerability in vedo-suite-project (CVE-2025-51056). Confidential information can be exposed externally.
CVE-2025-52078 Unrestricted File Upload in react (CVE-2025-52078)
vulnerability in react (CVE-2025-52078). Risk of unauthorized operations or information disclosure.
CVE-2012-10027 Unrestricted File Upload in wordpress (CVE-2012-10027)
vulnerability in wordpress (CVE-2012-10027). Risk of unauthorized operations or information disclosure. Exploitable via ``uploadify.php``.
CVE-2025-52239 Unrestricted File Upload in zkea (CVE-2025-52239)
vulnerability in zkea (CVE-2025-52239). Successful exploitation can lead to full system takeover.
CVE-2025-44139 Unrestricted File Upload in emlog (CVE-2025-44139)
vulnerability in emlog (CVE-2025-44139). Successful exploitation can lead to full system takeover.
CVE-2025-5243 OS Command Injection in CVE-2025-5243 (CVE-2025-5243)
OS command injection in CVE-2025-5243 (CVE-2025-5243). Successful exploitation can lead to full system takeover.
CVE-2025-46099 Unrestricted File Upload in pluck-cms (CVE-2025-46099)
vulnerability in pluck-cms (CVE-2025-46099). Successful exploitation can lead to full system takeover.
CVE-2015-10138 Unrestricted File Upload in wordpress (CVE-2015-10138)
vulnerability in wordpress (CVE-2015-10138). Successful exploitation can lead to full system takeover.
CVE-2025-23171 Unrestricted File Upload in versa-networks (CVE-2025-23171)
vulnerability in versa-networks (CVE-2025-23171). Successful exploitation can lead to full system takeover.
CVE-2025-46157 Unrestricted File Upload in efrotech (CVE-2025-46157)
vulnerability in efrotech (CVE-2025-46157). Successful exploitation can lead to full system takeover.
CVE-2025-0984 Cross-Site Scripting (XSS) in CVE-2025-0984 (CVE-2025-0984)
cross-site scripting in CVE-2025-0984 (CVE-2025-0984). Data can be tampered with by attackers.
CVE-2025-31324 KEV [KEV] Unrestricted File Upload in Sap netweaver (CVE-2025-31324)
vulnerability in Sap netweaver (CVE-2025-31324). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2025-29287 Unrestricted File Upload in mingsoft (CVE-2025-29287)
vulnerability in mingsoft (CVE-2025-29287). Successful exploitation can lead to full system takeover.
CVE-2024-57968 KEV [KEV] Unrestricted File Upload in Advantive veracore (CVE-2024-57968)
vulnerability in Advantive veracore (CVE-2024-57968). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-41339 Unrestricted File Upload in draytek (CVE-2024-41339)
vulnerability in draytek (CVE-2024-41339). Successful exploitation can lead to full system takeover.
CVE-2024-41340 Unrestricted File Upload in draytek (CVE-2024-41340)
vulnerability in draytek (CVE-2024-41340). Successful exploitation can lead to full system takeover.
CVE-2025-25783 Unrestricted File Upload in emlog (CVE-2025-25783)
vulnerability in emlog (CVE-2025-25783). Successful exploitation can lead to full system takeover.
CVE-2025-25784 Unrestricted File Upload in c (CVE-2025-25784)
vulnerability in c (CVE-2025-25784). Successful exploitation can lead to full system takeover.
CVE-2025-25790 Unrestricted File Upload in foxcms (CVE-2025-25790)
vulnerability in foxcms (CVE-2025-25790). Successful exploitation can lead to full system takeover.
CVE-2024-53345 Unrestricted File Upload in CVE-2024-53345 (CVE-2024-53345)
vulnerability in CVE-2024-53345 (CVE-2024-53345). Successful exploitation can lead to full system takeover.
CVE-2024-50623 KEV [KEV] Unrestricted File Upload in Cleo multiple-products (CVE-2024-50623)
vulnerability in Cleo multiple-products (CVE-2024-50623). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2024-51364 Unrestricted File Upload in CVE-2024-51364 (CVE-2024-51364)
vulnerability in CVE-2024-51364 (CVE-2024-51364). Successful exploitation can lead to full system takeover.
CVE-2024-51366 Unrestricted File Upload in CVE-2024-51366 (CVE-2024-51366)
vulnerability in CVE-2024-51366 (CVE-2024-51366). Successful exploitation can lead to full system takeover.
CVE-2024-11404 Vulnerability in django-filer (CVE-2024-11404)
vulnerability in django-filer (CVE-2024-11404). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
CVE-2024-48734 Unrestricted File Upload in CVE-2024-48734 (CVE-2024-48734)
vulnerability in CVE-2024-48734 (CVE-2024-48734). Successful exploitation can lead to full system takeover.
CVE-2024-46088 Unrestricted File Upload in CVE-2024-46088 (CVE-2024-46088)
vulnerability in CVE-2024-46088 (CVE-2024-46088). Successful exploitation can lead to full system takeover.
CVE-2024-39717 KEV [KEV] Unrestricted File Upload in Versa director (CVE-2024-39717)
vulnerability in Versa director (CVE-2024-39717). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-6127 Path Traversal in path-traversal (CVE-2024-6127)
path traversal in path-traversal (CVE-2024-6127). Successful exploitation can lead to full system takeover.
CVE-2024-33120 Unrestricted File Upload in roothub (CVE-2024-33120)
vulnerability in roothub (CVE-2024-33120). Successful exploitation can lead to full system takeover.
CVE-2024-32161 jizhiCMS 2.5 suffers from a File upload vulnerability.
jizhiCMS 2.5 suffers from a File upload vulnerability.
CVE-2024-28713 Unrestricted File Upload in mtons (CVE-2024-28713)
vulnerability in mtons (CVE-2024-28713). Successful exploitation can lead to full system takeover.
CVE-2024-29859 Unrestricted File Upload in misp-project (CVE-2024-29859)
vulnerability in misp-project (CVE-2024-29859). Successful exploitation can lead to full system takeover.
CVE-2024-25674 Unrestricted File Upload in misp-project (CVE-2024-25674)
vulnerability in misp-project (CVE-2024-25674). Successful exploitation can lead to full system takeover.
CVE-2023-6675 Unrestricted File Upload in nationalkeep (CVE-2023-6675)
vulnerability in nationalkeep (CVE-2023-6675). Successful exploitation can lead to full system takeover.
CVE-2023-51924 Unrestricted File Upload in yonyou (CVE-2023-51924)
vulnerability in yonyou (CVE-2023-51924). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →