CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2024-39904 HIGH
VNote < 3.18.1 - Remote Code Execution via Crafted file:// URI in Note
CVSS 8.8
CVE-2024-23317 MEDIUM
Controller 6000/7000 <9.10-8.70 - RCE
CVSS 6.3
CVE-2024-37149 HIGH
GLPI 0.85-10.0.15 - Authenticated Remote Code Execution via Plugin Loader Hijack
CVSS 7.2
CVE-2024-38049 MEDIUM
Windows Distributed Transaction Coordinator - Remote Code Execution
CVSS 6.6
CVE-2024-39303 MEDIUM
Weblate 4.14-5.6.1 - Path Traversal via Project Backup Restore
CVSS 4.4
CVE-2024-5334 HIGH
stitionai devika - Unauthenticated Arbitrary File Read via Snapshot Path Parameter
CVSS 7.5
CVE-2024-27175 MEDIUM
Toshiba Tec e-Studio multi-function peripheral (MFP) - Local File Inclusion via Remote Command Program
CVSS 4.4
CVE-2024-37295 HIGH
aimeos-core 2024.01.1-2024.04.4 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-36473 MEDIUM
Trend Micro VPN Proxy One Pro <5.8.1012 - Privilege Escalation
CVSS 5.3
CVE-2024-25975 MEDIUM
HAWKI - Authenticated Arbitrary File Overwrite via Path Traversal in Vote Function
CVSS 6.5
CVE-2024-28826 HIGH
Checkmk <2.3.0p4, <2.2.0p27, <2.1.0p44, 2.0.0 - Path Traversal
CVSS 8.8
CVE-2024-20366 HIGH
Cisco Crosswork NSO - Privilege Escalation
CVSS 7.8
CVE-2024-27945 HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted File Upload via Bulk Import Feature
CVSS 7.2
CVE-2024-27944 HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted Firmware Upload
CVSS 7.2
CVE-2024-27943 HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-25965 MEDIUM
Dell PowerScale OneFS 8.2.x-9.7.0.2 - Denial of Service via External Control of File Name or Path
CVSS 6.1
CVE-2024-4818 MEDIUM
Campcodes Online Laundry Management System 1.0 - File Inclusion
CVSS 5.3
CVE-2024-0100 MEDIUM
NVIDIA Triton Inference Server 22.09-24.04 - Denial of Service and Data Tampering via Tracing API
CVSS 6.5
CVE-2024-0087 CRITICAL
NVIDIA Triton Inference Server 20.10-23.12 - Arbitrary File Write via Logging Location
CVSS 9.0
CVE-2024-33860 MEDIUM
Logpoint SIEM < 7.4.0 - Local File Inclusion via File System Collector
CVSS 6.5
CVE-2024-33671 HIGH
Veritas Backup Exec <22.2 - Privilege Escalation
CVSS 7.7
CVE-2024-31492 HIGH
FortiClientMac <7.2.3, <7.0.10 - Code Injection
CVSS 8.2
CVE-2024-30265 HIGH
Collabora Online - Local File Inclusion
CVSS 7.5
CVE-2024-22178 MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
CVE-2024-21870 MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
Details
Vulnerabilities 519
Exploit Likelihood High