cwe-434
Safeguard articles tagged "cwe-434" — guides, analysis, and best practices for software supply chain and application security.
25 articles
CVE-2024-57968: Advantive VeraCore Unrestricted File Upload Vulnerability
CVE-2024-57968 affects Advantive VeraCore and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-03-10.
CVE-2025-31324: SAP NetWeaver Unrestricted File Upload Vulnerability
CVE-2025-31324 affects SAP NetWeaver and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-04-29.
CVE-2021-26828: OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2021-26828 affects OpenPLC ScadaBR and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-03.
CVE-2018-4063: Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2018-4063 affects Sierra Wireless AirLink ALEOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-12.
CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2025-52691 affects SmarterTools SmarterMail and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-01-26.
CVE-2024-7694: TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2024-7694 affects TeamT5 ThreatSonar Anti-Ransomware and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-17.
CVE-2025-2749: Kentico Xperience Path Traversal Vulnerability
CVE-2025-2749 affects Kentico Kentico Xperience and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-20.
CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability
CVE-2024-7399 affects Samsung MagicINFO 9 Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-24.
CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48908 affects JoomShaper SP Page Builder and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-07.
CVE-2026-48939: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48939 affects iCagenda iCagenda and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-10.
CVE-2026-56291: Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291 affects Balbooa Forms and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-07-10.
Arbitrary file upload vulnerabilities explained
Arbitrary file upload flaws (CWE-434) have caused breaches from Equifax to GitLab. Here's how they work, the CVEs that prove it, and how to stop them.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.