CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
450 vulnerabilities with CWE-73
CVE-2023-29324
MEDIUM
Windows MSHTML < - Privilege Escalation
CVSS 6.5
CVE-2023-2554
HIGH
unilogies/bumsys <2.2.0 - Path Traversal
CVSS 7.2
CVE-2023-30943
MEDIUM
Moodle 4.1.0-4.1.2 - Unauthenticated Arbitrary Folder Creation via TinyMCE Loader
CVSS 6.5
CVE-2023-2152
MEDIUM
SourceCodester Student Study Center Desk Management System 1.0 - Fi...
CVSS 5.3
CVE-2023-1105
HIGH
GitHub flatpressblog/flatpress <1.3 - Path Traversal
CVSS 8.1
CVE-2023-1070
HIGH
nilsteampassnet/teampass <3.0.0.22 - Path Traversal
CVSS 7.1
CVE-2023-21566
HIGH
Visual Studio - Privilege Escalation
CVSS 7.8
CVE-2023-21800
HIGH
Windows Installer < - Privilege Escalation
CVSS 7.8
CVE-2023-0003
MEDIUM
Palo Alto Networks Cortex XSOAR - Info Disclosure
CVSS 6.5
CVE-2022-4983
MEDIUM
TEC-IT TBarCode 11.15 - Remote File Creation via INI-based Licensing Handling
CVE-2022-39952
CRITICAL
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVSS 9.8
CVE-2022-43513
HIGH
Automation License Manager - Unauth RCE
CVSS 8.2
CVE-2022-45213
MEDIUM
perfsonar < 4.4.6 - Arbitrary File Read via file:// URL Parsing
CVSS 5.3
CVE-2022-34669
HIGH
NVIDIA Virtual GPU < 11.11 and Cloud Gaming < 527.27 - Unauthenticated Arbitrary File Access
CVSS 8.8
CVE-2022-31739
HIGH
Firefox < 101 and Firefox ESR < 91.10 - Path Traversal via Unescaped % Character in Download Path
CVSS 8.8
CVE-2022-23536
MEDIUM
Cortex <1.14.0 - Local File Inclusion
CVSS 6.5
CVE-2022-42893
HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42891
HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42734
HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42733
HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-42732
HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-2431
HIGH
Download Manager <= 3.2.50 - Arbitrary File Deletion via 'file[files]' Parameter
CVSS 8.1
CVE-2022-2638
MEDIUM
WordPress Plugin <4.4 - Path Traversal
CVSS 6.5
CVE-2022-32761
MEDIUM
WWBN AVideo 11.6 and dev master - Arbitrary File Read via aVideoEncoderReceiveImage
CVSS 6.5
CVE-2022-28710
MEDIUM
WWBN AVideo <11.6 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
450
Exploit Likelihood
High