CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
450 vulnerabilities with CWE-73
CVE-2024-38165
MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
CVE-2024-7497
MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-7496
MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-6714
HIGH
Provd <0.1.5 - Privilege Escalation
CVSS 8.8
CVE-2024-6937
LOW
Form Tools 3.1.1 - File Inclusion via Import Option List URL Parameter
CVSS 2.7
CVE-2024-6467
HIGH
BookingPress - Appointment Booking Calendar Plugin - Arbitrary File...
CVSS 8.8
CVE-2024-39904
HIGH
VNote < 3.18.1 - Remote Code Execution via Crafted file:// URI in Note
CVSS 8.8
CVE-2024-23317
MEDIUM
Controller 6000/7000 <9.10-8.70 - RCE
CVSS 6.3
CVE-2024-37149
HIGH
GLPI 0.85-10.0.15 - Authenticated Remote Code Execution via Plugin Loader Hijack
CVSS 7.2
CVE-2024-38049
MEDIUM
Windows Distributed Transaction Coordinator - Remote Code Execution
CVSS 6.6
CVE-2024-39303
MEDIUM
Weblate 4.14-5.6.1 - Path Traversal via Project Backup Restore
CVSS 4.4
CVE-2024-5334
HIGH
stitionai devika - Unauthenticated Arbitrary File Read via Snapshot Path Parameter
CVSS 7.5
CVE-2024-27175
MEDIUM
Toshiba Tec e-Studio multi-function peripheral (MFP) - Local File Inclusion via Remote Command Program
CVSS 4.4
CVE-2024-37295
HIGH
aimeos-core 2024.01.1-2024.04.4 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-36473
MEDIUM
Trend Micro VPN Proxy One Pro <5.8.1012 - Privilege Escalation
CVSS 5.3
CVE-2024-25975
MEDIUM
HAWKI - Authenticated Arbitrary File Overwrite via Path Traversal in Vote Function
CVSS 6.5
CVE-2024-28826
HIGH
Checkmk <2.3.0p4, <2.2.0p27, <2.1.0p44, 2.0.0 - Path Traversal
CVSS 8.8
CVE-2024-20366
HIGH
Cisco Crosswork NSO - Privilege Escalation
CVSS 7.8
CVE-2024-27945
HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted File Upload via Bulk Import Feature
CVSS 7.2
CVE-2024-27944
HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted Firmware Upload
CVSS 7.2
CVE-2024-27943
HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-25965
MEDIUM
Dell PowerScale OneFS 8.2.x-9.7.0.2 - Denial of Service via External Control of File Name or Path
CVSS 6.1
CVE-2024-4818
MEDIUM
Campcodes Online Laundry Management System 1.0 - File Inclusion
CVSS 5.3
CVE-2024-0100
MEDIUM
NVIDIA Triton Inference Server 22.09-24.04 - Denial of Service and Data Tampering via Tracing API
CVSS 6.5
CVE-2024-0087
CRITICAL
NVIDIA Triton Inference Server 20.10-23.12 - Arbitrary File Write via Logging Location
CVSS 9.0
Details
Vulnerabilities
450
Exploit Likelihood
High