Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,276 CVEs tagged with CWE-4341,505 Critical, 1,643 High, 886 Medium, 241 Low, 1 Unrated.

CVE-2026-16332

Published Jul 21, 2026

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16331

Published Jul 21, 2026

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Mal…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16330

Published Jul 21, 2026

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argume…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16329

Published Jul 21, 2026

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Han…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16327

Published Jul 21, 2026

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument F…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16324

Published Jul 20, 2026

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-53593

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restri…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-61900

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file up…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-61424

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated f…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
25.0
Public PoC observed

CVE-2026-60032

Published Jul 20, 2026

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, le…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-63429

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` re…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45797

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored i…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-57311

Published Jul 20, 2026

Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution. Because vendor c…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-16226

Published Jul 19, 2026

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation o…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-48062

Published Jul 17, 2026

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed ex…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-36669

Published Jul 17, 2026

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-13352

Published Jul 17, 2026

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Uplo…

CVSS 8.8 · High
evidence mentions
9
Buzz score
34.5

CVE-2026-12684

Published Jul 16, 2026

The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50124

Published Jul 15, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/uplo…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-61457

Published Jul 15, 2026

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspec…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-11579

Published Jul 15, 2026

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upl…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-15677

Published Jul 14, 2026

A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-58409

Published Jul 13, 2026

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-49972

Published Jul 13, 2026

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP…

CVSS 7.7 · High
evidence mentions
3
Buzz score
20.4
Showing 76-100 of 4,276 CVEsPage 4 of 172