CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

449 vulnerabilities with CWE-73
CVE-2025-29708 CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
CVE-2025-0124 LOW
Palo Alto Networks PAN-OS - Auth Bypass
CVSS 3.8
CVE-2025-29819 MEDIUM
Azure Portal Windows Admin Center - Info Disclosure
CVSS 6.2
CVE-2025-3431 HIGH
ZoomSounds - WordPress Wave Audio Player with Playlist <6.91 - Info...
CVSS 7.5
CVE-2025-2004 CRITICAL
Simple WP Events <1.8.17 - Path Traversal
CVSS 9.1
CVE-2025-3033 HIGH
Firefox < 137.0 - Arbitrary File Upload via Malicious .url Shortcut
CVSS 7.7
CVE-2025-2982 MEDIUM
Legrand SMS PowerView 1.x - File Inclusion
CVSS 6.3
CVE-2025-1911 LOW
Product Import Export for WooCommerce - Product CSV Suite <2.5.0 - ...
CVSS 2.7
CVE-2025-27147 HIGH
GLPI Inventory Plugin <1.5.0 - Privilege Escalation
CVSS 8.2
CVE-2025-1972 LOW
WordPress <2.6.2 - Privilege Escalation
CVSS 2.7
CVE-2025-0452 HIGH
eosphoros-ai/DB-GPT - Privilege Escalation
CVSS 8.2
CVE-2025-29930 MEDIUM
imFAQ <1.0.1 - Local File Inclusion
CVE-2025-24996 MEDIUM
Windows 10 1507-24H2 and Windows Server 2008-2012 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2025-24054 MEDIUM KEV
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2025-1730 MEDIUM
Simple Download Counter <2.0 - Info Disclosure
CVSS 6.5
CVE-2025-25478 MEDIUM
syspass 3.2.0-3.2.10 - Source Code Disclosure via Account File Upload Filename Mismanagement
CVSS 6.5
CVE-2025-25761 HIGH
HkCms <2.3.2.240702 - Code Injection
CVSS 7.2
CVE-2025-1686 MEDIUM
io.pebbletemplates:pebble - Path Traversal
CVSS 6.8
CVE-2025-27137 MEDIUM
Dependency-Track <4.12.6 - Code Injection
CVSS 4.4
CVE-2025-0111 MEDIUM KEV
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 6.5
CVE-2025-0109 MEDIUM
Palo Alto Networks PAN-OS - Unauthenticated File Deletion
CVE-2025-21377 MEDIUM
NTLM Hash Disclosure Spoofing - Info Disclosure
CVSS 6.5
CVE-2025-0630 MEDIUM
Western Telematic - Local File Inclusion
CVSS 6.5
CVE-2025-0851 CRITICAL
Ai.djl API < 0.31.1 - Path Traversal
CVSS 9.8
CVE-2025-0105 CRITICAL
Palo Alto Networks Expedition - Info Disclosure
CVSS 9.1
Details
Vulnerabilities 449
Exploit Likelihood High