CWE-434Base15 in KEV

Unrestricted Upload of File with Dangerous Type

Draft in the CWE catalog · 2,463 CVEs mapped

2,463
CVEs mapped
15
In KEV
8.2
Median CVSS
What it is

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Recent examples
7.3cvss
CVE-2026-86272

Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload

A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

HIGHno explanation yet
epss
5.3cvss
CVE-2026-86239

liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload

A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

MEDIUMno explanation yet
epss
9.8cvss
CVE-2026-44402

CVE-2026-44402 - CRITICAL Severity Vulnerability

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.

CRITICALno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-434
Abstraction
Base
Structure
Simple
Status
Draft
References (6)