CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
450 vulnerabilities with CWE-73
CVE-2024-33860
MEDIUM
Logpoint SIEM < 7.4.0 - Local File Inclusion via File System Collector
CVSS 6.5
CVE-2024-33671
HIGH
Veritas Backup Exec <22.2 - Privilege Escalation
CVSS 7.7
CVE-2024-31492
HIGH
FortiClientMac <7.2.3, <7.0.10 - Code Injection
CVSS 8.2
CVE-2024-30265
HIGH
Collabora Online - Local File Inclusion
CVSS 7.5
CVE-2024-22178
MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
CVE-2024-21870
MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
CVE-2024-2917
MEDIUM
Campcodes House Rental Management System 1.0 - File Inclusion
CVSS 5.4
CVE-2024-1603
HIGH
PaddlePaddle Paddle <2.6.0 - Info Disclosure
CVSS 7.5
CVE-2024-23634
MEDIUM
GeoServer < 2.23.5 and 2.24.2 - Authenticated Arbitrary File Renaming via REST Coverage Store or Data Store API
CVSS 6.0
CVE-2024-26185
MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
CVE-2024-2155
MEDIUM
SourceCodester Best POS Management System 1.0 - File Inclusion
CVSS 4.3
CVE-2024-2150
MEDIUM
SourceCodester Insurance Management System 1.0 - File Inclusion
CVSS 5.3
CVE-2024-25117
MEDIUM
php-svg-lib <0.5.2 - Remote Code Execution via PHAR font-family URL
CVSS 6.8
CVE-2024-0728
MEDIUM
ForU CMS <2020-06-23 - File Inclusion
CVSS 4.7
CVE-2024-20652
HIGH
Windows HTML Platforms < - Privilege Escalation
CVSS 8.1
CVE-2024-0265
MEDIUM
SourceCodester Clinic Queuing System 1.0 - File Inclusion
CVSS 6.3
CVE-2023-45588
HIGH
FortiClientMac <7.2.3 - Path Traversal
CVSS 8.2
CVE-2023-5816
MEDIUM
Code Explorer <1.4.5 - Info Disclosure
CVSS 4.9
CVE-2023-47147
MEDIUM
IBM Sterling Secure Proxy <6.1.0 - Info Disclosure
CVSS 5.9
CVE-2023-26282
MEDIUM
IBM Watson CP4D Data Stores <4.6.4 - Privilege Escalation
CVSS 4.2
CVE-2023-49864
MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_image Parameter
CVSS 6.5
CVE-2023-49863
MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_webpimage Parameter
CVSS 6.5
CVE-2023-49862
MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_gifimage Parameter
CVSS 6.5
CVE-2023-49738
HIGH
WWBN AVideo - Arbitrary File Read via image404Raw.php
CVSS 7.5
CVE-2023-47862
CRITICAL
WWBN AVideo - Local File Inclusion and Remote Code Execution via getLanguageFromBrowser
CVSS 9.8
Details
Vulnerabilities
450
Exploit Likelihood
High