CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2026-64816
MEDIUM
RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath
CVSS 6.5
CVE-2026-52680
ANALYSIS PENDING
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
CVE-2026-15382
MEDIUM
Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts
CVSS 6.5
CVE-2026-67429
CRITICAL
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
CVSS 10.0
CVE-2026-56390
MEDIUM
Arbitrary Output Location Change in GNU Bison
CVE-2026-57916
MEDIUM
Arbitrary Path Execution via CPS URI in proCertum SmartSign
CVE-2026-65896
HIGH
Grav API Plugin before 1.0.10 Path Traversal via move
CVSS 7.1
CVE-2026-14551
HIGH
Local Privilege Escalation in servereye client (sensorhub)
CVSS 8.8
CVE-2026-47425
MEDIUM
Rattler vulnerable to entry-point path traversal in noarch:python install (arbitrary file write)
CVE-2026-15724
HIGH
Path traversal in Progress ShareFile Storage Zones Controller (SZC)
CVSS 8.7
CVE-2026-56452
HIGH
Apache MINA SSHD: Path traversal in SCP file reception
CVSS 7.5
CVE-2026-58484
HIGH
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
CVSS 7.1
CVE-2026-45139
MEDIUM
CI4MS < 0.31.9.0 Fileeditor - Arbitrary File Deletion or Rename
CVSS 6.5
CVE-2026-50162
MEDIUM
oras-go: file store write outside workingDir via symlink traversal
CVE-2026-9587
HIGH
Authenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal
CVE-2026-44019
HIGH
Docling Core has insufficient validation of image reference URIs
CVSS 8.1
CVE-2026-46336
HIGH
Manyfold: Authenticated Path Traversal via File Rename
CVSS 7.1
CVE-2026-12979
MEDIUM
FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer
CVSS 5.5
CVE-2026-15921
LOW
nvm path traversal via a malicious mirror's LTS codename writes outside the alias directory
CVSS 3.1
CVE-2026-50148
CRITICAL
Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
CVSS 10.0
CVE-2026-61873
HIGH
Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename
CVSS 8.1
CVE-2026-8920
HIGH
Asus Aura Wallpaper Service < v2.1.15.0 - External Control of File Name or Path
CVE-2026-50462
HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-55002
HIGH
Microsoft SQL Server Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-54108
MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVSS 6.5
Details
Vulnerabilities
519
Exploit Likelihood
High