CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2025-36506 MEDIUM
RICOH Streamline NX V3 PC Client <3.242.0 - Path Traversal
CVSS 6.5
CVE-2025-47956 MEDIUM
Windows Security App - Path Traversal
CVSS 5.5
CVE-2025-33053 HIGH KEV
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
CVSS 8.8
CVE-2025-48067 MEDIUM
OctoPrint <1.11.1 - Info Disclosure
CVSS 5.4
CVE-2025-49138 MEDIUM
HAX CMS PHP <11.0.0 - Local File Inclusion
CVSS 6.5
CVE-2025-48783 HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-48781 HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-32802 MEDIUM
ISC Kea 2.4.0-2.4.1, 2.6.0-2.6.2, 2.7.0-2.7.8 - Arbitrary File Write via Configuration and API Directives
CVSS 6.1
CVE-2025-4603 CRITICAL
eMagicOne Store Manager - Path Traversal
CVSS 9.1
CVE-2025-4602 MEDIUM
eMagicOne Store Manager for WooCommerce <1.2.5 - Info Disclosure
CVSS 5.9
CVE-2025-2409 CRITICAL
ABB ASPECT-Enterprise NEXUS Series MATRIX Series <= 3.08.03 - Authenticated Arbitrary File Write
CVSS 9.1
CVE-2025-3812 HIGH
WPBot Pro Wordpress Chatbot <13.6.2 - Privilege Escalation
CVSS 8.1
CVE-2025-26646 HIGH
Microsoft .NET, Visual Studio, and Build Tools - Path Spoofing via External Control of File Name or Path
CVSS 8.0
CVE-2025-26684 MEDIUM
Microsoft Defender for Endpoint - Privilege Escalation
CVSS 6.7
CVE-2025-3419 HIGH
Eventin plugin <4.0.26 - Info Disclosure
CVSS 7.5
CVE-2025-46762 HIGH
Apache Parquet < 1.15.2 - Remote Code Execution via Parquet-Avro Schema Parsing
CVSS 8.1
CVE-2025-1056 MEDIUM
AXIS Camera Station Pro < 6.8.43213 - Authenticated Arbitrary File Write via File Modification
CVSS 6.1
CVE-2025-43951 CRITICAL
LabVantage <8.8.0.13 HF6 - Path Traversal
CVSS 9.8
CVE-2025-3103 HIGH
CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - ...
CVSS 7.5
CVE-2025-29709 CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
CVE-2025-29708 CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
CVE-2025-0124 LOW
Palo Alto Networks PAN-OS - Auth Bypass
CVSS 3.8
CVE-2025-29819 MEDIUM
Azure Portal Windows Admin Center - Info Disclosure
CVSS 6.2
CVE-2025-3431 HIGH
ZoomSounds - WordPress Wave Audio Player with Playlist <6.91 - Info...
CVSS 7.5
CVE-2025-2004 CRITICAL
Simple WP Events <1.8.17 - Path Traversal
CVSS 9.1
Details
Vulnerabilities 519
Exploit Likelihood High