CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2024-46909 CRITICAL
WhatsUp Gold < 24.0.1 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-10492 LOW
Keycloak < 26.0.6 - Authenticated Sensitive Information Disclosure via Vault File Access
CVSS 2.7
CVE-2024-43451 MEDIUM KEV
NTLM Hash Disclosure Spoofing - Info Disclosure
CVSS 6.5
CVE-2024-10672 LOW
Multiple Page Generator Plugin - Path Traversal
CVSS 2.7
CVE-2024-5823 CRITICAL
gaizhenbiao/chuanhuchatgpt <= 20240410 - File Overwrite and Denial of Service via Configuration File Tampering
CVSS 9.1
CVE-2024-41183 HIGH
Trend Micro VPN <5.8.1012 - Privilege Escalation
CVSS 7.8
CVE-2024-9575 HIGH
Pretix Widget <1.0.6 - Local File Inclusion
CVE-2024-43615 HIGH
Microsoft OpenSSH for Windows Remote Code Execution
CVSS 7.1
CVE-2024-43581 HIGH
Microsoft OpenSSH for Windows - Remote Code Execution
CVSS 7.1
CVE-2024-38029 HIGH
Microsoft OpenSSH for Windows - RCE
CVSS 7.5
CVE-2024-38040 HIGH
Esri Portal for ArcGIS <11.2 - Info Disclosure
CVSS 7.5
CVE-2024-9275 MEDIUM
jeanmarc77 123solar <1.8.4.5 - File Inclusion
CVSS 6.3
CVE-2024-9142 CRITICAL
Olgu Computer Systems e-Belediye <2.0.642 - Path Traversal
CVSS 9.8
CVE-2024-21545 HIGH
Proxmox Virtual Environment - Privilege Escalation
CVSS 8.2
CVE-2024-7626 HIGH
WP Delicious Recipe Plugin < 1.6.9 - Authenticated Arbitrary File Movement and Reading
CVSS 8.1
CVE-2024-8517 CRITICAL
SPIP <4.3.2-4.1.18 - Command Injection
CVSS 9.8
CVE-2024-7744 MEDIUM
WS_FTP Server < 8.8.8 - Authenticated Path Traversal via Web Transfer Module
CVSS 6.5
CVE-2024-7911 MEDIUM
SourceCodester Simple Online Bidding System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-38173 MEDIUM
Microsoft Outlook - Remote Code Execution
CVSS 6.7
CVE-2024-38165 MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
CVE-2024-7497 MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-7496 MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-6714 HIGH
Provd <0.1.5 - Privilege Escalation
CVSS 8.8
CVE-2024-6937 LOW
Form Tools 3.1.1 - File Inclusion via Import Option List URL Parameter
CVSS 2.7
CVE-2024-6467 HIGH
BookingPress - Appointment Booking Calendar Plugin - Arbitrary File...
CVSS 8.8
Details
Vulnerabilities 519
Exploit Likelihood High