CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

450 vulnerabilities with CWE-73
CVE-2023-29324 MEDIUM
Windows MSHTML < - Privilege Escalation
CVSS 6.5
CVE-2023-2554 HIGH
unilogies/bumsys <2.2.0 - Path Traversal
CVSS 7.2
CVE-2023-30943 MEDIUM
Moodle 4.1.0-4.1.2 - Unauthenticated Arbitrary Folder Creation via TinyMCE Loader
CVSS 6.5
CVE-2023-2152 MEDIUM
SourceCodester Student Study Center Desk Management System 1.0 - Fi...
CVSS 5.3
CVE-2023-1105 HIGH
GitHub flatpressblog/flatpress <1.3 - Path Traversal
CVSS 8.1
CVE-2023-1070 HIGH
nilsteampassnet/teampass <3.0.0.22 - Path Traversal
CVSS 7.1
CVE-2023-21566 HIGH
Visual Studio - Privilege Escalation
CVSS 7.8
CVE-2023-21800 HIGH
Windows Installer < - Privilege Escalation
CVSS 7.8
CVE-2023-0003 MEDIUM
Palo Alto Networks Cortex XSOAR - Info Disclosure
CVSS 6.5
CVE-2022-4983 MEDIUM
TEC-IT TBarCode 11.15 - Remote File Creation via INI-based Licensing Handling
CVE-2022-39952 CRITICAL
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVSS 9.8
CVE-2022-43513 HIGH
Automation License Manager - Unauth RCE
CVSS 8.2
CVE-2022-45213 MEDIUM
perfsonar < 4.4.6 - Arbitrary File Read via file:// URL Parsing
CVSS 5.3
CVE-2022-34669 HIGH
NVIDIA Virtual GPU < 11.11 and Cloud Gaming < 527.27 - Unauthenticated Arbitrary File Access
CVSS 8.8
CVE-2022-31739 HIGH
Firefox < 101 and Firefox ESR < 91.10 - Path Traversal via Unescaped % Character in Download Path
CVSS 8.8
CVE-2022-23536 MEDIUM
Cortex <1.14.0 - Local File Inclusion
CVSS 6.5
CVE-2022-42893 HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42891 HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42734 HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42733 HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-42732 HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-2431 HIGH
Download Manager <= 3.2.50 - Arbitrary File Deletion via 'file[files]' Parameter
CVSS 8.1
CVE-2022-2638 MEDIUM
WordPress Plugin <4.4 - Path Traversal
CVSS 6.5
CVE-2022-32761 MEDIUM
WWBN AVideo 11.6 and dev master - Arbitrary File Read via aVideoEncoderReceiveImage
CVSS 6.5
CVE-2022-28710 MEDIUM
WWBN AVideo <11.6 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 450
Exploit Likelihood High