CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2025-64739
MEDIUM
Zoom Meeting SDK < 6.5.10 - Unauthenticated Information Disclosure via File Path Control
CVSS 4.3
CVE-2025-64738
MEDIUM
Zoom Workplace for macOS <6.5.10 - Info Disclosure
CVSS 5.0
CVE-2025-59511
HIGH
Windows WLAN Service - Privilege Escalation
CVSS 7.8
CVE-2025-20614
MEDIUM
Intel(R) CIP <WIN_DCA_2.4.0.11001 - Privilege Escalation
CVSS 6.7
CVE-2025-8998
LOW
AXIS OS 6.50.0-12.7.27 - Authenticated DoS via File Upload
CVSS 3.1
CVE-2025-11451
HIGH
Auto Amazon Links - Amazon Associates Affiliate Plugin <5.4.3 - Inf...
CVSS 7.5
CVE-2025-12915
MEDIUM
70mai X200 <20251019 - File Inclusion
CVSS 6.4
CVE-2025-64486
CRITICAL
calibre < 8.14.0 - Arbitrary File Write and Remote Code Execution via FB2 Binary Asset Filename
CVE-2025-12137
MEDIUM
Import WP <= 2.14.16 - Authenticated Arbitrary File Read via attach_file()
CVSS 4.9
CVE-2025-62611
HIGH
aiomysql < 0.3.0 - Arbitrary File Read via LOAD_LOCAL Instruction
CVE-2025-8050
MEDIUM
OpenText Flipper 3.1.2 - Path Traversal
CVSS 6.5
CVE-2025-8048
MEDIUM
OpenText Flipper 3.1.2 - Path Traversal via Stored Document ID
CVSS 6.5
CVE-2025-11738
MEDIUM
Media Library Assistant <3.29 - Info Disclosure
CVSS 5.3
CVE-2025-62382
HIGH
Frigate < 0.16.2 - Authenticated Arbitrary File Read via Export Thumbnail Path
CVSS 7.7
CVE-2025-59483
MEDIUM
Configuration Utility - Info Disclosure
CVSS 6.5
CVE-2025-59292
HIGH
Confidential Azure Container Instances - Privilege Escalation
CVSS 8.2
CVE-2025-59291
HIGH
Confidential Azure Container Instances - Privilege Escalation
CVSS 8.2
CVE-2025-59244
MEDIUM
Windows Core Shell - Path Traversal
CVSS 6.5
CVE-2025-59200
HIGH
Data Sharing Service Client - Spoofing
CVSS 7.7
CVE-2025-59185
MEDIUM
Windows Core Shell - Path Traversal
CVSS 6.5
CVE-2025-35053
MEDIUM
Newforma Project Center < 2024.3 - Authenticated Path Traversal and Arbitrary File Deletion via MarkupServices.ashx
CVSS 6.4
CVE-2025-10494
HIGH
Motors - Car Dealership & Classified Listings Plugin <1.4.89 - Priv...
CVSS 8.1
CVE-2025-10306
LOW
Backup Bolt <1.4.1 - Path Traversal
CVSS 3.8
CVE-2025-58769
LOW
auth0-php 3.3.0-8.16.0 - Path Traversal via Bulk User Import Endpoint
CVSS 3.3
CVE-2025-6237
CRITICAL
invokeai < 6.7.0 - Path Traversal and Arbitrary File Deletion via Image Download Endpoint
CVSS 9.8
Details
Vulnerabilities
519
Exploit Likelihood
High