CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

450 vulnerabilities with CWE-73
CVE-2024-38165 MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
CVE-2024-7497 MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-7496 MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-6714 HIGH
Provd <0.1.5 - Privilege Escalation
CVSS 8.8
CVE-2024-6937 LOW
Form Tools 3.1.1 - File Inclusion via Import Option List URL Parameter
CVSS 2.7
CVE-2024-6467 HIGH
BookingPress - Appointment Booking Calendar Plugin - Arbitrary File...
CVSS 8.8
CVE-2024-39904 HIGH
VNote < 3.18.1 - Remote Code Execution via Crafted file:// URI in Note
CVSS 8.8
CVE-2024-23317 MEDIUM
Controller 6000/7000 <9.10-8.70 - RCE
CVSS 6.3
CVE-2024-37149 HIGH
GLPI 0.85-10.0.15 - Authenticated Remote Code Execution via Plugin Loader Hijack
CVSS 7.2
CVE-2024-38049 MEDIUM
Windows Distributed Transaction Coordinator - Remote Code Execution
CVSS 6.6
CVE-2024-39303 MEDIUM
Weblate 4.14-5.6.1 - Path Traversal via Project Backup Restore
CVSS 4.4
CVE-2024-5334 HIGH
stitionai devika - Unauthenticated Arbitrary File Read via Snapshot Path Parameter
CVSS 7.5
CVE-2024-27175 MEDIUM
Toshiba Tec e-Studio multi-function peripheral (MFP) - Local File Inclusion via Remote Command Program
CVSS 4.4
CVE-2024-37295 HIGH
aimeos-core 2024.01.1-2024.04.4 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-36473 MEDIUM
Trend Micro VPN Proxy One Pro <5.8.1012 - Privilege Escalation
CVSS 5.3
CVE-2024-25975 MEDIUM
HAWKI - Authenticated Arbitrary File Overwrite via Path Traversal in Vote Function
CVSS 6.5
CVE-2024-28826 HIGH
Checkmk <2.3.0p4, <2.2.0p27, <2.1.0p44, 2.0.0 - Path Traversal
CVSS 8.8
CVE-2024-20366 HIGH
Cisco Crosswork NSO - Privilege Escalation
CVSS 7.8
CVE-2024-27945 HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted File Upload via Bulk Import Feature
CVSS 7.2
CVE-2024-27944 HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted Firmware Upload
CVSS 7.2
CVE-2024-27943 HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-25965 MEDIUM
Dell PowerScale OneFS 8.2.x-9.7.0.2 - Denial of Service via External Control of File Name or Path
CVSS 6.1
CVE-2024-4818 MEDIUM
Campcodes Online Laundry Management System 1.0 - File Inclusion
CVSS 5.3
CVE-2024-0100 MEDIUM
NVIDIA Triton Inference Server 22.09-24.04 - Denial of Service and Data Tampering via Tracing API
CVSS 6.5
CVE-2024-0087 CRITICAL
NVIDIA Triton Inference Server 20.10-23.12 - Arbitrary File Write via Logging Location
CVSS 9.0
Details
Vulnerabilities 450
Exploit Likelihood High