Weaknesses of type CWE-434

3,091 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-20354CRITICALCisco Unified Contact Center Express Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-46157CRITICALAn issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave requesEPSS 0.9%CVE-2020-37084HIGHSchool ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-1328MEDIUMGuizhou 115cms index unrestricted uploadEPSS 0.9%CVE-2021-34076HIGHFile Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file EPSS 0.9%CVE-2021-47757HIGHChikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)EPSS 0.9%CVE-2022-43436HIGHHWA JIUH DIGITAL TECHNOLOGY LTD. EasyTest - Arbitrary File UploadEPSS 0.9%CVE-2024-12853HIGHModula Image Gallery <= 2.11.10 - Authenticated (Author+) Arbitrary File UploadEPSS 0.9%CVE-2026-37748HIGHVisitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.EPSS 0.9%CVE-2023-28699HIGHWADE DIGITAL DESIGN CO, LTD. FANTSY - Arbitrary File UploadEPSS 0.9%CVE-2026-49827CRITICALWebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)EPSS 0.9%CVE-2023-1744MEDIUMIBOS htaccess unrestricted uploadEPSS 0.9%CVE-2024-31286CRITICALWordPress WP Photo Album Plus plugin < 8.6.03.005 - Arbitrary File Upload vulnerabilityEPSS 0.9%CVE-2025-10647HIGHEmbed PDF for WPForms <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 0.9%CVE-2023-50922HIGHAn issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code bEPSS 0.9%CVE-2022-44401CRITICALOnline Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.EPSS 0.9%CVE-2026-88738HIGHJazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attaEPSS 0.9%CVE-2020-22539HIGHAn arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploadiEPSS 0.9%CVE-2015-0796MEDIUMopen build service source server symlink exploitation via source patchEPSS 0.9%CVE-2024-8615CRITICALWP JobSearch <= 2.6.7 - Unauthenticated Arbitrary File UploadEPSS 0.9%