Skip to main content

CWE archive

CWE-351 CVEs

Programmatic archive

15 CVEs tagged with CWE-3511 Critical, 6 High, 6 Medium, 2 Low, 0 Unrated.

CVE-2026-15305

Published Jul 14, 2026

Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced serv…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-31951

Published May 6, 2026

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permi…

CVSS 8.8 · High

CVE-2026-41341

Published Apr 23, 2026

OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages in extensions/discord/src/mon…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-65960

Published Nov 25, 2025

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54413

Published Jul 26, 2025

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain an inconsistency in MethodNode, which can be exploite…

CVSS 8.7 · High

CVE-2025-54412

Published Jul 26, 2025

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be…

CVSS 8.7 · High

CVE-2025-47939

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of an…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32035

Published Apr 8, 2025

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), t…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-45676

Published Dec 3, 2024

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insufficient file type distinction.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38831

Published Aug 23, 2023

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may in…

CVSS 7.8 · High
evidence mentions
24
Buzz score
76.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-2866

Published Jun 7, 2023

If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1642

Published Jun 16, 2022

A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10134

Published May 19, 2020

Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairing devices via adjacent access when the unauthenticated use…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1