cwe-434
Safeguard articles tagged "cwe-434" — guides, analysis, and best practices for software supply chain and application security.
25 articles
CVE-2021-31207: Microsoft Exchange Server Security Feature Bypass Vulnerability
CVE-2021-31207 affects Microsoft Exchange Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2018-15961: Adobe ColdFusion Unrestricted File Upload Vulnerability
CVE-2018-15961 affects Adobe ColdFusion and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-27860: FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit
CVE-2021-27860 affects FatPipe WARP, IPVPN, and MPVPN software and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-10.
CVE-2020-13671: Drupal core Un-restricted Upload of File
CVE-2020-13671 affects Drupal Drupal core and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-18.
CVE-2019-8394: Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
CVE-2019-8394 affects Zoho ManageEngine and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-25213: WordPress File Manager Plugin Remote Code Execution Vulnerability
CVE-2020-25213 affects WordPress File Manager Plugin and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-20022: SonicWall Email Security Unrestricted Upload of File Vulnerability
CVE-2021-20022 affects SonicWall SonicWall Email Security and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-8260: Ivanti Pulse Connect Secure Code Execution Vulnerability
CVE-2020-8260 affects Ivanti Pulse Connect Secure and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2017-12615: Apache Tomcat on Windows Remote Code Execution Vulnerability
CVE-2017-12615 affects Apache Tomcat and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-25.
CVE-2017-12617: Apache Tomcat Remote Code Execution Vulnerability
CVE-2017-12617 affects Apache Tomcat and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-25.
CVE-2024-39717: Versa Director Dangerous File Type Upload Vulnerability
CVE-2024-39717 affects Versa Director and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-08-23.
CVE-2024-50623: Cleo Multiple Products Unrestricted File Upload Vulnerability
CVE-2024-50623 affects Cleo Multiple Products and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-12-13.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.