Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-434 · Unrestricted file uploadDefinition on MITRE ↗Clear

23 results

CVE-2026-56291
2026-07-10
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Balbooa

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

CWE-434 · Unrestricted file upload
Refsbalbooa.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-13
CVE-2026-48939
2026-07-10
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CWE-434 · Unrestricted file upload
Refsicagenda.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-13
CVE-2026-48908
2026-07-07
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CWE-434 · Unrestricted file upload
Refsextensions.joomla.orgBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-10
CVE-2024-7399
2026-04-24
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

CWE-22 · Path traversalCWE-434 · Unrestricted file upload
Refssecurity.samsungtv.comnvd.nist.gov
Federal remediation due 2026-05-08
CVE-2025-2749
2026-04-20
Kentico Xperience Path Traversal Vulnerability
Kentico

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

CWE-22 · Path traversalCWE-434 · Unrestricted file upload
Refsdevnet.kentico.comnvd.nist.gov
Federal remediation due 2026-05-04
CVE-2024-7694
2026-02-17
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
TeamT5

TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system commands on the server.

CWE-434 · Unrestricted file upload
Refsteamt5.orgtwcert.org.twnvd.nist.gov
Federal remediation due 2026-03-10
CVE-2025-52691
2026-01-26
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type VulnerabilityRansomware
SmarterTools

SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

CWE-434 · Unrestricted file upload
Refssmartertools.comcsa.gov.sgnvd.nist.gov
Federal remediation due 2026-02-16
CVE-2018-4063
2025-12-12
Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
Sierra Wireless

Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-434 · Unrestricted file upload
Refscisa.govsource.sierrawireless.comsource.sierrawireless.comnvd.nist.gov
Federal remediation due 2026-01-02
CVE-2021-26828
2025-12-03
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC

OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

CWE-434 · Unrestricted file upload
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2025-12-24
CVE-2025-31324
2025-04-29
SAP NetWeaver Unrestricted File Upload VulnerabilityRansomware
SAP

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

CWE-434 · Unrestricted file upload
Refsme.sap.comnvd.nist.gov
Federal remediation due 2025-05-20
CVE-2024-57968
2025-03-10
Advantive VeraCore Unrestricted File Upload Vulnerability
Advantive

Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.

CWE-434 · Unrestricted file upload
Refsadvantive.my.site.comnvd.nist.gov
Federal remediation due 2025-03-31
CVE-2024-50623
2024-12-13
Cleo Multiple Products Unrestricted File Upload VulnerabilityRansomware
Cleo

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated privileges.

CWE-434 · Unrestricted file upload
Refssupport.cleo.comnvd.nist.gov
Federal remediation due 2025-01-03
CVE-2024-39717
2024-08-23
Versa Director Dangerous File Type Upload Vulnerability
Versa

The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image.

CWE-434 · Unrestricted file upload
Refsversa-networks.comnvd.nist.gov
Federal remediation due 2024-09-13
CVE-2017-12617
2022-03-25
Apache Tomcat Remote Code Execution Vulnerability
Apache

When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2017-12615
2022-03-25
Apache Tomcat on Windows Remote Code Execution VulnerabilityRansomware
Apache

When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2020-13671
2022-01-18
Drupal core Un-restricted Upload of File
Drupal

Improper sanitization in the extension file names is present in Drupal core.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-07-18
CVE-2021-27860
2022-01-10
FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit
FatPipe / WARP, IPVPN, and MPVPN software

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-01-24
CVE-2021-31207
2021-11-03
Microsoft Exchange Server Security Feature Bypass VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

CWE-20 · Improper input validationCWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-20022
2021-11-03
SonicWall Email Security Unrestricted Upload of File VulnerabilityRansomware
SonicWall

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2020-8260
2021-11-03
Ivanti Pulse Connect Secure Code Execution Vulnerability
Ivanti

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

CWE-434 · Unrestricted file upload
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2020-25213
2021-11-03
WordPress File Manager Plugin Remote Code Execution Vulnerability
WordPress

WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-8394
2021-11-03
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
Zoho

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2018-15961
2021-11-03
Adobe ColdFusion Unrestricted File Upload Vulnerability
Adobe

Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

CWE-434 · Unrestricted file upload
Refsnvd.nist.gov
Federal remediation due 2022-05-03