Weaknesses of type CWE-434

3,089 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-9872HIGHInsufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker toEPSS 13.5%CVE-2022-45359CRITICALWordPress YITH WooCommerce Gift Cards Premium Plugin <= 3.19.0 is vulnerable to Arbitrary File UploadEPSS 13.5%CVE-2025-13065HIGHStarter Templates <= 4.4.41 - Authenticated (Author+) Arbitrary File Upload via WXR Upload BypassEPSS 13.5%CVE-2024-8232HIGHiniNet Solutions SpiderControl SCADA Web Server Unrestricted Upload of File with Dangerous TypeEPSS 13.1%CVE-2013-1916—In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on thEPSS 12.8%CVE-2024-25832HIGHF-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of danEPSS 12.8%CVE-2022-2419HIGHURVE Web Manager upload.php unrestricted uploadEPSS 12.8%CVE-2023-38098HIGHNETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 12.7%CVE-2025-53119HIGHSecurden Unified PAM Unauthenticated Unrestricted File UploadEPSS 12.3%CVE-2021-43258HIGHCartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated accEPSS 11.6%CVE-2025-61687HIGHFlowiseAI/Flosise has File Upload vulnerabilityEPSS 11.1%CVE-2020-15645HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. AlthougEPSS 10.7%CVE-2025-61808CRITICALColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)EPSS 10.6%CVE-2024-6127CRITICALBC Security Empire Path Traversal RCEEPSS 10.3%CVE-2025-54441HIGHUnrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affEPSS 10.3%CVE-2025-50286HIGHA Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/toEPSS 9.6%CVE-2020-8866MEDIUMThis vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. AuEPSS 9.6%CVE-2024-29272MEDIUMArbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and oEPSS 9.4%CVE-2025-54439HIGHUnrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affEPSS 9.0%CVE-2017-11154—Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attaEPSS 8.6%