CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2024-39904
HIGH
VNote < 3.18.1 - Remote Code Execution via Crafted file:// URI in Note
CVSS 8.8
CVE-2024-23317
MEDIUM
Controller 6000/7000 <9.10-8.70 - RCE
CVSS 6.3
CVE-2024-37149
HIGH
GLPI 0.85-10.0.15 - Authenticated Remote Code Execution via Plugin Loader Hijack
CVSS 7.2
CVE-2024-38049
MEDIUM
Windows Distributed Transaction Coordinator - Remote Code Execution
CVSS 6.6
CVE-2024-39303
MEDIUM
Weblate 4.14-5.6.1 - Path Traversal via Project Backup Restore
CVSS 4.4
CVE-2024-5334
HIGH
stitionai devika - Unauthenticated Arbitrary File Read via Snapshot Path Parameter
CVSS 7.5
CVE-2024-27175
MEDIUM
Toshiba Tec e-Studio multi-function peripheral (MFP) - Local File Inclusion via Remote Command Program
CVSS 4.4
CVE-2024-37295
HIGH
aimeos-core 2024.01.1-2024.04.4 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-36473
MEDIUM
Trend Micro VPN Proxy One Pro <5.8.1012 - Privilege Escalation
CVSS 5.3
CVE-2024-25975
MEDIUM
HAWKI - Authenticated Arbitrary File Overwrite via Path Traversal in Vote Function
CVSS 6.5
CVE-2024-28826
HIGH
Checkmk <2.3.0p4, <2.2.0p27, <2.1.0p44, 2.0.0 - Path Traversal
CVSS 8.8
CVE-2024-20366
HIGH
Cisco Crosswork NSO - Privilege Escalation
CVSS 7.8
CVE-2024-27945
HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted File Upload via Bulk Import Feature
CVSS 7.2
CVE-2024-27944
HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Unrestricted Firmware Upload
CVSS 7.2
CVE-2024-27943
HIGH
RUGGEDCOM CROSSBOW < 5.5 - Authenticated Arbitrary File Upload and Remote Code Execution
CVSS 7.2
CVE-2024-25965
MEDIUM
Dell PowerScale OneFS 8.2.x-9.7.0.2 - Denial of Service via External Control of File Name or Path
CVSS 6.1
CVE-2024-4818
MEDIUM
Campcodes Online Laundry Management System 1.0 - File Inclusion
CVSS 5.3
CVE-2024-0100
MEDIUM
NVIDIA Triton Inference Server 22.09-24.04 - Denial of Service and Data Tampering via Tracing API
CVSS 6.5
CVE-2024-0087
CRITICAL
NVIDIA Triton Inference Server 20.10-23.12 - Arbitrary File Write via Logging Location
CVSS 9.0
CVE-2024-33860
MEDIUM
Logpoint SIEM < 7.4.0 - Local File Inclusion via File System Collector
CVSS 6.5
CVE-2024-33671
HIGH
Veritas Backup Exec <22.2 - Privilege Escalation
CVSS 7.7
CVE-2024-31492
HIGH
FortiClientMac <7.2.3, <7.0.10 - Code Injection
CVSS 8.2
CVE-2024-30265
HIGH
Collabora Online - Local File Inclusion
CVSS 7.5
CVE-2024-22178
MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
CVE-2024-21870
MEDIUM
Open Automation Software OAS Platform <19.00.0057 - File Write
CVSS 4.9
Details
Vulnerabilities
519
Exploit Likelihood
High