Weaknesses of type CWE-434

3,113 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-9314CRITICALDeveloper Tools <= 1.1.3 – Unauthenticated Arbitrary File UploadEPSS 0.3%CVE-2026-46426HIGHBudibase: Unrestricted Upload of File with Dangerous TypeEPSS 0.3%CVE-2025-55267MEDIUMHCL Aftermarket DPC is affected by Unrestricted File Upload vulnerabilityEPSS 0.3%CVE-2025-54460HIGHAVEVA PI Integrator Unrestricted Upload of File with Dangerous TypeEPSS 0.3%CVE-2021-47899MEDIUMYetiShare File Hosting Script 5.1.0 Remote File Upload SSRF VulnerabilityEPSS 0.3%CVE-2025-66837MEDIUMA file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/MalwareEPSS 0.3%CVE-2025-54693CRITICALWordPress Form Block Plugin <= 1.5.5 - Arbitrary File Upload VulnerabilityEPSS 0.3%CVE-2024-25801MEDIUMSKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not tEPSS 0.3%CVE-2026-1969MEDIUMThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File UploadEPSS 0.3%CVE-2025-33023MEDIUMA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (AllEPSS 0.3%CVE-2026-14906MEDIUMMalicious webpage titles could allow overwriting of bundled PDF resources when saving webpages as PDFs in Firefox for iOSEPSS 0.3%CVE-2024-36987MEDIUMInsecure File Upload in the indexing/preview REST endpointEPSS 0.3%CVE-2025-59525HIGHHorilla has Improper Input Sanitization Leading to XSS and Admin Account TakeoverEPSS 0.3%CVE-2024-50652MEDIUMA file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.EPSS 0.3%CVE-2025-24505HIGHThis vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploadiEPSS 0.3%CVE-2026-11474MEDIUMKushan2k student-management-system Registration Endpoint RegisterService.php unrestricted uploadEPSS 0.3%CVE-2025-40678MEDIUMUnrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del EmpleadoEPSS 0.3%CVE-2022-27562MEDIUMHCL Domino Volt is affected by an unrestricted upload of a dangerous file typeEPSS 0.3%CVE-2022-42449MEDIUMHCL Domino Volt is affected by an unrestricted upload of a dangerous file typeEPSS 0.3%CVE-2022-44760MEDIUMHCL Leap is affected by an unrestricted upload of file with dangerous type vulnerabilityEPSS 0.3%