CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

450 vulnerabilities with CWE-73
CVE-2022-2400 MEDIUM
dompdf < 2.0.0 - Path Traversal via Untrusted File Path
CVSS 5.3
CVE-2022-34765 MEDIUM
X80 advanced RTU Communication Module - Path Traversal
CVSS 5.5
CVE-2022-24900 CRITICAL
Piano LED Visualizer < 1.3 - Path Traversal via os.path.join
CVSS 9.9
CVE-2022-20789 MEDIUM
Cisco Unified Communications Manager - Privilege Escalation
CVSS 4.9
CVE-2022-0246 MEDIUM
WordPress iQ Block Country <1.2.13 - Path Traversal
CVSS 4.9
CVE-2022-0593 MEDIUM
Login with phone number WP <1.3.7 - DoS
CVSS 6.5
CVE-2021-47871 HIGH
Hestia Control Panel 1.3.2 - File Write
CVSS 8.8
CVE-2021-47746 HIGH
NodeBB Plugin Emoji 3.2.1 - Path Traversal
CVSS 7.5
CVE-2021-4472 MEDIUM
Mistral-OpenStack - Info Disclosure
CVSS 6.5
CVE-2021-4332 MEDIUM
Plus Addons for Elementor <4.1.9(pro) & 2.0.6(free) - Info Disclosure
CVSS 6.5
CVE-2021-24966 MEDIUM
Error Log Viewer <1.1.1 - Privilege Escalation
CVSS 4.9
CVE-2021-3845 HIGH
ws_scrcpy < 0.7.1 - Path Traversal
CVSS 7.5
CVE-2021-34761 MEDIUM
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 4.4
CVE-2021-38477 CRITICAL
Multiple API Functions - Info Disclosure
CVSS 9.8
CVE-2021-3626 HIGH
Multipass < 1.7.0 - Unauthenticated Privilege Escalation via Localhost TCP Control Socket
CVSS 8.8
CVE-2021-1306 MEDIUM
Cisco EPN Manager, ISE, Prime Infrastructure - Path Traversal
CVSS 4.4
CVE-2021-22539 HIGH
VScode-bazel <0.4.1 - Code Injection
CVSS 8.2
CVE-2021-27250 MEDIUM
D-Link DAP-2020 v1.01rc001 - Info Disclosure
CVSS 6.5
CVE-2021-21343 MEDIUM
XStream <1.4.16 - Code Injection
CVSS 5.3
CVE-2020-37080 CRITICAL
webTareas 2.0.p8 - Privilege Escalation
CVSS 9.8
CVE-2020-37078 HIGH
i-doit Open Source CMDB 1.14.1 - File Deletion
CVSS 8.8
CVE-2020-36878 HIGH
ReQuest Serious Play Media Player 3.0 - Info Disclosure
CVE-2020-36868 HIGH
Nagios XI <5.7.3 - Privilege Escalation
CVSS 7.8
CVE-2020-36772 MEDIUM
CloudLinux CageFS <7.0.8.2 - Info Disclosure
CVSS 4.4
CVE-2020-25161 HIGH
WebAccess/SCADA <9.0 - Code Injection
CVSS 8.8
Details
Vulnerabilities 450
Exploit Likelihood High