CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
449 vulnerabilities with CWE-73
CVE-2025-29708
CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
CVE-2025-0124
LOW
Palo Alto Networks PAN-OS - Auth Bypass
CVSS 3.8
CVE-2025-29819
MEDIUM
Azure Portal Windows Admin Center - Info Disclosure
CVSS 6.2
CVE-2025-3431
HIGH
ZoomSounds - WordPress Wave Audio Player with Playlist <6.91 - Info...
CVSS 7.5
CVE-2025-2004
CRITICAL
Simple WP Events <1.8.17 - Path Traversal
CVSS 9.1
CVE-2025-3033
HIGH
Firefox < 137.0 - Arbitrary File Upload via Malicious .url Shortcut
CVSS 7.7
CVE-2025-2982
MEDIUM
Legrand SMS PowerView 1.x - File Inclusion
CVSS 6.3
CVE-2025-1911
LOW
Product Import Export for WooCommerce - Product CSV Suite <2.5.0 - ...
CVSS 2.7
CVE-2025-27147
HIGH
GLPI Inventory Plugin <1.5.0 - Privilege Escalation
CVSS 8.2
CVE-2025-1972
LOW
WordPress <2.6.2 - Privilege Escalation
CVSS 2.7
CVE-2025-0452
HIGH
eosphoros-ai/DB-GPT - Privilege Escalation
CVSS 8.2
CVE-2025-29930
MEDIUM
imFAQ <1.0.1 - Local File Inclusion
CVE-2025-24996
MEDIUM
Windows 10 1507-24H2 and Windows Server 2008-2012 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2025-24054
MEDIUM
KEV
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2025-1730
MEDIUM
Simple Download Counter <2.0 - Info Disclosure
CVSS 6.5
CVE-2025-25478
MEDIUM
syspass 3.2.0-3.2.10 - Source Code Disclosure via Account File Upload Filename Mismanagement
CVSS 6.5
CVE-2025-25761
HIGH
HkCms <2.3.2.240702 - Code Injection
CVSS 7.2
CVE-2025-1686
MEDIUM
io.pebbletemplates:pebble - Path Traversal
CVSS 6.8
CVE-2025-27137
MEDIUM
Dependency-Track <4.12.6 - Code Injection
CVSS 4.4
CVE-2025-0111
MEDIUM
KEV
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 6.5
CVE-2025-0109
MEDIUM
Palo Alto Networks PAN-OS - Unauthenticated File Deletion
CVE-2025-21377
MEDIUM
NTLM Hash Disclosure Spoofing - Info Disclosure
CVSS 6.5
CVE-2025-0630
MEDIUM
Western Telematic - Local File Inclusion
CVSS 6.5
CVE-2025-0851
CRITICAL
Ai.djl API < 0.31.1 - Path Traversal
CVSS 9.8
CVE-2025-0105
CRITICAL
Palo Alto Networks Expedition - Info Disclosure
CVSS 9.1
Details
Vulnerabilities
449
Exploit Likelihood
High