CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2024-46909
CRITICAL
WhatsUp Gold < 24.0.1 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2024-10492
LOW
Keycloak < 26.0.6 - Authenticated Sensitive Information Disclosure via Vault File Access
CVSS 2.7
CVE-2024-43451
MEDIUM
KEV
NTLM Hash Disclosure Spoofing - Info Disclosure
CVSS 6.5
CVE-2024-10672
LOW
Multiple Page Generator Plugin - Path Traversal
CVSS 2.7
CVE-2024-5823
CRITICAL
gaizhenbiao/chuanhuchatgpt <= 20240410 - File Overwrite and Denial of Service via Configuration File Tampering
CVSS 9.1
CVE-2024-41183
HIGH
Trend Micro VPN <5.8.1012 - Privilege Escalation
CVSS 7.8
CVE-2024-9575
HIGH
Pretix Widget <1.0.6 - Local File Inclusion
CVE-2024-43615
HIGH
Microsoft OpenSSH for Windows Remote Code Execution
CVSS 7.1
CVE-2024-43581
HIGH
Microsoft OpenSSH for Windows - Remote Code Execution
CVSS 7.1
CVE-2024-38029
HIGH
Microsoft OpenSSH for Windows - RCE
CVSS 7.5
CVE-2024-38040
HIGH
Esri Portal for ArcGIS <11.2 - Info Disclosure
CVSS 7.5
CVE-2024-9275
MEDIUM
jeanmarc77 123solar <1.8.4.5 - File Inclusion
CVSS 6.3
CVE-2024-9142
CRITICAL
Olgu Computer Systems e-Belediye <2.0.642 - Path Traversal
CVSS 9.8
CVE-2024-21545
HIGH
Proxmox Virtual Environment - Privilege Escalation
CVSS 8.2
CVE-2024-7626
HIGH
WP Delicious Recipe Plugin < 1.6.9 - Authenticated Arbitrary File Movement and Reading
CVSS 8.1
CVE-2024-8517
CRITICAL
SPIP <4.3.2-4.1.18 - Command Injection
CVSS 9.8
CVE-2024-7744
MEDIUM
WS_FTP Server < 8.8.8 - Authenticated Path Traversal via Web Transfer Module
CVSS 6.5
CVE-2024-7911
MEDIUM
SourceCodester Simple Online Bidding System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-38173
MEDIUM
Microsoft Outlook - Remote Code Execution
CVSS 6.7
CVE-2024-38165
MEDIUM
Windows Compressed Folder Tampering - Info Disclosure
CVSS 6.5
CVE-2024-7497
MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-7496
MEDIUM
itsourcecode Airline Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2024-6714
HIGH
Provd <0.1.5 - Privilege Escalation
CVSS 8.8
CVE-2024-6937
LOW
Form Tools 3.1.1 - File Inclusion via Import Option List URL Parameter
CVSS 2.7
CVE-2024-6467
HIGH
BookingPress - Appointment Booking Calendar Plugin - Arbitrary File...
CVSS 8.8
Details
Vulnerabilities
519
Exploit Likelihood
High