CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2025-36506
MEDIUM
RICOH Streamline NX V3 PC Client <3.242.0 - Path Traversal
CVSS 6.5
CVE-2025-47956
MEDIUM
Windows Security App - Path Traversal
CVSS 5.5
CVE-2025-33053
HIGH
KEV
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
CVSS 8.8
CVE-2025-48067
MEDIUM
OctoPrint <1.11.1 - Info Disclosure
CVSS 5.4
CVE-2025-49138
MEDIUM
HAX CMS PHP <11.0.0 - Local File Inclusion
CVSS 6.5
CVE-2025-48783
HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-48781
HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-32802
MEDIUM
ISC Kea 2.4.0-2.4.1, 2.6.0-2.6.2, 2.7.0-2.7.8 - Arbitrary File Write via Configuration and API Directives
CVSS 6.1
CVE-2025-4603
CRITICAL
eMagicOne Store Manager - Path Traversal
CVSS 9.1
CVE-2025-4602
MEDIUM
eMagicOne Store Manager for WooCommerce <1.2.5 - Info Disclosure
CVSS 5.9
CVE-2025-2409
CRITICAL
ABB ASPECT-Enterprise NEXUS Series MATRIX Series <= 3.08.03 - Authenticated Arbitrary File Write
CVSS 9.1
CVE-2025-3812
HIGH
WPBot Pro Wordpress Chatbot <13.6.2 - Privilege Escalation
CVSS 8.1
CVE-2025-26646
HIGH
Microsoft .NET, Visual Studio, and Build Tools - Path Spoofing via External Control of File Name or Path
CVSS 8.0
CVE-2025-26684
MEDIUM
Microsoft Defender for Endpoint - Privilege Escalation
CVSS 6.7
CVE-2025-3419
HIGH
Eventin plugin <4.0.26 - Info Disclosure
CVSS 7.5
CVE-2025-46762
HIGH
Apache Parquet < 1.15.2 - Remote Code Execution via Parquet-Avro Schema Parsing
CVSS 8.1
CVE-2025-1056
MEDIUM
AXIS Camera Station Pro < 6.8.43213 - Authenticated Arbitrary File Write via File Modification
CVSS 6.1
CVE-2025-43951
CRITICAL
LabVantage <8.8.0.13 HF6 - Path Traversal
CVSS 9.8
CVE-2025-3103
HIGH
CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - ...
CVSS 7.5
CVE-2025-29709
CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
CVE-2025-29708
CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
CVE-2025-0124
LOW
Palo Alto Networks PAN-OS - Auth Bypass
CVSS 3.8
CVE-2025-29819
MEDIUM
Azure Portal Windows Admin Center - Info Disclosure
CVSS 6.2
CVE-2025-3431
HIGH
ZoomSounds - WordPress Wave Audio Player with Playlist <6.91 - Info...
CVSS 7.5
CVE-2025-2004
CRITICAL
Simple WP Events <1.8.17 - Path Traversal
CVSS 9.1
Details
Vulnerabilities
519
Exploit Likelihood
High