CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

449 vulnerabilities with CWE-73
CVE-2024-12875 MEDIUM
Easy Digital Downloads <= 3.3.2 - Authenticated Path Traversal via File Download
CVSS 4.9
CVE-2024-12066 HIGH
SMSA Shipping(official) plugin - Path Traversal
CVSS 8.8
CVE-2024-4230 HIGH
Edgecross Basic Software <1.00 - Path Traversal
CVSS 7.8
CVE-2024-11838 CRITICAL
PlexTrac <2.8.1 - Local Code Inclusion
CVSS 9.8
CVE-2024-12357 MEDIUM
SourceCodester Best House Rental Management System 1.0 - File Inclu...
CVSS 4.3
CVE-2024-46909 CRITICAL
WhatsUp Gold < 24.0.1 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-10492 LOW
Keycloak < 26.0.6 - Authenticated Sensitive Information Disclosure via Vault File Access
CVSS 2.7
CVE-2024-43451 MEDIUM KEV
NTLM Hash Disclosure Spoofing - Info Disclosure
CVSS 6.5
CVE-2024-10672 LOW
Multiple Page Generator Plugin - Path Traversal
CVSS 2.7
CVE-2024-5823 CRITICAL
gaizhenbiao/chuanhuchatgpt <= 20240410 - File Overwrite and Denial of Service via Configuration File Tampering
CVSS 9.1
CVE-2024-41183 HIGH
Trend Micro VPN <5.8.1012 - Privilege Escalation
CVSS 7.8
CVE-2024-9575 HIGH
Pretix Widget <1.0.6 - Local File Inclusion
CVE-2024-43615 HIGH
Microsoft OpenSSH for Windows Remote Code Execution
CVSS 7.1
CVE-2024-43581 HIGH
Microsoft OpenSSH for Windows - Remote Code Execution
CVSS 7.1
CVE-2024-38029 HIGH
Microsoft OpenSSH for Windows - RCE
CVSS 7.5
CVE-2024-38040 HIGH
Esri Portal for ArcGIS <11.2 - Info Disclosure
CVSS 7.5
CVE-2024-9275 MEDIUM
jeanmarc77 123solar <1.8.4.5 - File Inclusion
CVSS 6.3
CVE-2024-9142 CRITICAL
Olgu Computer Systems e-Belediye <2.0.642 - Path Traversal
CVSS 9.8
CVE-2024-21545 HIGH
Proxmox Virtual Environment - Privilege Escalation
CVSS 8.2
CVE-2024-7626 HIGH
WP Delicious Recipe Plugin < 1.6.9 - Authenticated Arbitrary File Movement and Reading
CVSS 8.1
CVE-2024-8517 CRITICAL
SPIP <4.3.2-4.1.18 - Command Injection
CVSS 9.8
CVE-2024-7744 MEDIUM
WS_FTP Server < 8.8.8 - Authenticated Path Traversal via Web Transfer Module
CVSS 6.5
CVE-2024-7911 MEDIUM
SourceCodester Simple Online Bidding System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-38173 MEDIUM
Microsoft Outlook - Remote Code Execution
CVSS 6.7
CVE-2024-38165 MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 449
Exploit Likelihood High