CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

450 vulnerabilities with CWE-73
CVE-2023-47171 MEDIUM
WWBN AVideo 11.6 and dev master commit 15fed957fb - Arbitrary File Read via aVideoEncoder.json.php chunkFile Path
CVSS 6.5
CVE-2023-6569 HIGH
h2o - Path Traversal
CVSS 8.2
CVE-2023-36019 CRITICAL
Microsoft Power Platform Connector - Open Redirect
CVSS 9.6
CVE-2023-6618 MEDIUM
SourceCodester Simple Student Attendance System 1.0 - File Inclusion
CVSS 5.5
CVE-2023-5247 HIGH
Mitsubishi Electric GX Works3 - Malicious Code Execution via Crafted Project File
CVSS 7.8
CVE-2023-40194 HIGH
Foxit Reader 12.1.3.15356 - Code Injection
CVSS 8.8
CVE-2023-39542 HIGH
Foxit Reader 12.1.3.15356 - Remote Code Execution via JavaScript saveAs API
CVSS 8.8
CVE-2023-35985 HIGH
Foxit Reader 12.1.3.15356 - Code Injection
CVSS 8.8
CVE-2023-34982 MEDIUM
AVEVA Batch Management < 2020 - Authenticated Denial of Service via File Deletion
CVSS 5.5
CVE-2023-46851 MEDIUM
Apache Allura <1.16.0 - Info Disclosure
CVSS 4.9
CVE-2023-20114 MEDIUM
Cisco Firepower Management Center - RCE
CVSS 6.5
CVE-2023-43074 MEDIUM
Dell Unity 5.3 - Arbitrary File Creation
CVSS 5.2
CVE-2023-36634 HIGH
FortiAP-U <7.0.0, <6.2.5, <=6.0, <=5.4 - Command Injection
CVSS 7.1
CVE-2023-36764 HIGH
Microsoft SharePoint Server - Privilege Escalation
CVSS 8.8
CVE-2023-4634 CRITICAL
Media Library Assistant <3.09 - RCE
CVSS 9.8
CVE-2023-32615 MEDIUM
Open Automation Software OAS Platform <18.00.0072 - File Write
CVSS 6.5
CVE-2023-4749 MEDIUM
SourceCodester Inventory Management System 1.0 - File Inclusion
CVSS 6.3
CVE-2023-20234 MEDIUM
Cisco FXOS Software - Privilege Escalation
CVSS 4.4
CVE-2023-35384 MEDIUM
Windows HTML Platforms < - Privilege Escalation
CVSS 5.4
CVE-2023-4191 MEDIUM
SourceCodester Resort Reservation System 1.0 - File Inclusion
CVSS 6.3
CVE-2023-3643 HIGH
Boss Mini 1.4.0 Build 6221 - File Inclusion
CVSS 7.3
CVE-2023-35308 MEDIUM
Microsoft Windows MSHTML Platform - Security Feature Bypass
CVSS 6.5
CVE-2023-3256 HIGH
Advantech R-SeeNet <2.4.22 - Info Disclosure
CVSS 8.8
CVE-2023-28603 HIGH
Zoom VDI client installer <5.14.0 - Info Disclosure
CVSS 7.7
CVE-2023-0008 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 4.4
Details
Vulnerabilities 450
Exploit Likelihood High