CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2025-3033
HIGH
Firefox < 137.0 - Arbitrary File Upload via Malicious .url Shortcut
CVSS 7.7
CVE-2025-2982
MEDIUM
Legrand SMS PowerView 1.x - File Inclusion
CVSS 6.3
CVE-2025-1911
LOW
Product Import Export for WooCommerce - Product CSV Suite <2.5.0 - ...
CVSS 2.7
CVE-2025-27147
HIGH
GLPI Inventory Plugin <1.5.0 - Privilege Escalation
CVSS 8.2
CVE-2025-1972
LOW
WordPress <2.6.2 - Privilege Escalation
CVSS 2.7
CVE-2025-0452
HIGH
eosphoros-ai/DB-GPT - Privilege Escalation
CVSS 8.2
CVE-2025-29930
MEDIUM
imFAQ <1.0.1 - Local File Inclusion
CVE-2025-24996
MEDIUM
Windows 10 1507-24H2 and Windows Server 2008-2012 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2025-24054
MEDIUM
KEV
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2025-1730
MEDIUM
Simple Download Counter <2.0 - Info Disclosure
CVSS 6.5
CVE-2025-25478
MEDIUM
syspass 3.2.0-3.2.10 - Source Code Disclosure via Account File Upload Filename Mismanagement
CVSS 6.5
CVE-2025-25761
HIGH
HkCms <2.3.2.240702 - Code Injection
CVSS 7.2
CVE-2025-1686
MEDIUM
io.pebbletemplates:pebble - Path Traversal
CVSS 6.8
CVE-2025-27137
MEDIUM
Dependency-Track <4.12.6 - Code Injection
CVSS 4.4
CVE-2025-0111
MEDIUM
KEV
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 6.5
CVE-2025-0109
MEDIUM
Palo Alto Networks PAN-OS - Unauthenticated File Deletion
CVE-2025-21377
MEDIUM
NTLM Hash Disclosure Spoofing - Info Disclosure
CVSS 6.5
CVE-2025-0630
MEDIUM
Western Telematic - Local File Inclusion
CVSS 6.5
CVE-2025-0851
CRITICAL
Ai.djl API < 0.31.1 - Path Traversal
CVSS 9.8
CVE-2025-0105
CRITICAL
Palo Alto Networks Expedition - Info Disclosure
CVSS 9.1
CVE-2025-0211
MEDIUM
Campcodes School Faculty Scheduling System 1.0 - File Inclusion
CVSS 6.3
CVE-2025-0202
MEDIUM
TCS BaNCS 10 - File Inclusion via /REPORTS/REPORTS_SHOW_FILE.jsp FilePath Parameter
CVSS 5.5
CVE-2024-5986
CRITICAL
Ai.h2o H2o-core - Remote Code Execution
CVSS 9.1
CVE-2024-13984
CRITICAL
QiAnXin TianQing Management Center <=6.7.0.4130 - Path Traversal
CVE-2024-1244
CRITICAL
OSSEC HIDS <3.8.0 - Info Disclosure
Details
Vulnerabilities
519
Exploit Likelihood
High