Vulnerabilities (CVE)

Filtered by CWE-434
Total 4396 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-8433 1 Jtbc 1 Jtbc Php 2026-06-17 5.0 MEDIUM 7.5 HIGH
JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file.
CVE-2019-8404 1 Webiness Inventory Project 1 Webiness Inventory 2026-06-17 5.5 MEDIUM 6.5 MEDIUM
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages.
CVE-2019-8394 1 Zohocorp 1 Manageengine Servicedesk Plus 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
CVE-2019-8371 1 Open-emr 1 Openemr 2026-06-17 9.0 HIGH 7.2 HIGH
OpenEMR v5.0.1-6 allows code execution.
CVE-2019-8362 1 Dedecms 1 Dedecms 2026-06-17 5.0 MEDIUM 7.5 HIGH
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg, .png, or .gif is present as a substring, and does not otherwise check the file name or content).
CVE-2019-8293 1 Abcprintf 1 Upload-image-with-ajax 2026-06-17 7.5 HIGH 9.8 CRITICAL
Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.
CVE-2019-8140 1 Magento 1 Magento 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
An unrestricted file upload vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated admin user can manipulate the Synchronization feature in the Media File Storage of the database to transform uploaded JPEG file into a PHP file.
CVE-2019-8114 1 Magento 1 Magento 2026-06-17 6.5 MEDIUM 7.2 HIGH
A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to import features can execute arbitrary code via crafted configuration archive file upload.
CVE-2019-8093 1 Magento 1 Magento 2026-06-17 6.5 MEDIUM 8.8 HIGH
An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage file upload controller for downloadable products to read/delete an arbitary files.
CVE-2019-7930 1 Magento 1 Magento 2026-06-17 9.0 HIGH 7.2 HIGH
A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with administrator privileges to the import feature can make modifications to a configuration file, resulting in potentially unauthorized removal of file upload restrictions. This can result in arbitrary code execution when a malicious file is then uploaded and executed on the system.
CVE-2019-7912 1 Magento 1 Magento 2026-06-17 6.5 MEDIUM 7.2 HIGH
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.
CVE-2019-7861 1 Magento 1 Magento 2026-06-17 5.0 MEDIUM 7.5 HIGH
Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
CVE-2019-7838 1 Adobe 1 Coldfusion 2026-06-17 10.0 HIGH 9.8 CRITICAL
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2019-7816 1 Adobe 1 Coldfusion 2026-06-17 10.0 HIGH 9.8 CRITICAL
ColdFusion versions Update 2 and earlier, Update 9 and earlier, and Update 17 and earlier have a file upload restriction bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
CVE-2019-7721 1 Nconsulting 1 Nc-cms 2026-06-17 5.0 MEDIUM 7.5 HIGH
lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.
CVE-2019-7684 1 Inxedu 1 Inxedu 2026-06-17 10.0 HIGH 9.8 CRITICAL
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The attacker uses the /video/uploadvideo fileType parameter to change the list of acceptable extensions from jpg,gif,png,jpeg to jpg,gif,png,jsp,jpeg.
CVE-2019-7669 1 Primasystems 1 Flexair 2026-06-17 9.0 HIGH 8.8 HIGH
Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges.
CVE-2019-7274 1 Optergy 2 Enterprise, Proton 2026-06-17 10.0 HIGH 9.8 CRITICAL
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
CVE-2019-7268 1 Nortekcontrol 4 Linear Emerge 5000p, Linear Emerge 5000p Firmware, Linear Emerge 50p and 1 more 2026-06-17 10.0 HIGH 10.0 CRITICAL
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
CVE-2019-7257 1 Nortekcontrol 4 Linear Emerge Elite, Linear Emerge Elite Firmware, Linear Emerge Essential and 1 more 2026-06-17 7.5 HIGH 10.0 CRITICAL
Linear eMerge E3-Series devices allow Unrestricted File Upload.