CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2025-64739 MEDIUM
Zoom Meeting SDK < 6.5.10 - Unauthenticated Information Disclosure via File Path Control
CVSS 4.3
CVE-2025-64738 MEDIUM
Zoom Workplace for macOS <6.5.10 - Info Disclosure
CVSS 5.0
CVE-2025-59511 HIGH
Windows WLAN Service - Privilege Escalation
CVSS 7.8
CVE-2025-20614 MEDIUM
Intel(R) CIP <WIN_DCA_2.4.0.11001 - Privilege Escalation
CVSS 6.7
CVE-2025-8998 LOW
AXIS OS 6.50.0-12.7.27 - Authenticated DoS via File Upload
CVSS 3.1
CVE-2025-11451 HIGH
Auto Amazon Links - Amazon Associates Affiliate Plugin <5.4.3 - Inf...
CVSS 7.5
CVE-2025-12915 MEDIUM
70mai X200 <20251019 - File Inclusion
CVSS 6.4
CVE-2025-64486 CRITICAL
calibre < 8.14.0 - Arbitrary File Write and Remote Code Execution via FB2 Binary Asset Filename
CVE-2025-12137 MEDIUM
Import WP <= 2.14.16 - Authenticated Arbitrary File Read via attach_file()
CVSS 4.9
CVE-2025-62611 HIGH
aiomysql < 0.3.0 - Arbitrary File Read via LOAD_LOCAL Instruction
CVE-2025-8050 MEDIUM
OpenText Flipper 3.1.2 - Path Traversal
CVSS 6.5
CVE-2025-8048 MEDIUM
OpenText Flipper 3.1.2 - Path Traversal via Stored Document ID
CVSS 6.5
CVE-2025-11738 MEDIUM
Media Library Assistant <3.29 - Info Disclosure
CVSS 5.3
CVE-2025-62382 HIGH
Frigate < 0.16.2 - Authenticated Arbitrary File Read via Export Thumbnail Path
CVSS 7.7
CVE-2025-59483 MEDIUM
Configuration Utility - Info Disclosure
CVSS 6.5
CVE-2025-59292 HIGH
Confidential Azure Container Instances - Privilege Escalation
CVSS 8.2
CVE-2025-59291 HIGH
Confidential Azure Container Instances - Privilege Escalation
CVSS 8.2
CVE-2025-59244 MEDIUM
Windows Core Shell - Path Traversal
CVSS 6.5
CVE-2025-59200 HIGH
Data Sharing Service Client - Spoofing
CVSS 7.7
CVE-2025-59185 MEDIUM
Windows Core Shell - Path Traversal
CVSS 6.5
CVE-2025-35053 MEDIUM
Newforma Project Center < 2024.3 - Authenticated Path Traversal and Arbitrary File Deletion via MarkupServices.ashx
CVSS 6.4
CVE-2025-10494 HIGH
Motors - Car Dealership & Classified Listings Plugin <1.4.89 - Priv...
CVSS 8.1
CVE-2025-10306 LOW
Backup Bolt <1.4.1 - Path Traversal
CVSS 3.8
CVE-2025-58769 LOW
auth0-php 3.3.0-8.16.0 - Path Traversal via Bulk User Import Endpoint
CVSS 3.3
CVE-2025-6237 CRITICAL
invokeai < 6.7.0 - Path Traversal and Arbitrary File Deletion via Image Download Endpoint
CVSS 9.8
Details
Vulnerabilities 519
Exploit Likelihood High