CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2023-21566 HIGH
Visual Studio - Privilege Escalation
CVSS 7.8
CVE-2023-21800 HIGH
Windows Installer < - Privilege Escalation
CVSS 7.8
CVE-2023-0003 MEDIUM
Palo Alto Networks Cortex XSOAR - Info Disclosure
CVSS 6.5
CVE-2022-4983 MEDIUM
TEC-IT TBarCode 11.15 - Remote File Creation via INI-based Licensing Handling
CVE-2022-39952 CRITICAL
Fortinet FortiNAC keyUpload.jsp arbitrary file write
CVSS 9.8
CVE-2022-43513 HIGH
Automation License Manager - Unauth RCE
CVSS 8.2
CVE-2022-45213 MEDIUM
perfsonar < 4.4.6 - Arbitrary File Read via file:// URL Parsing
CVSS 5.3
CVE-2022-34669 HIGH
NVIDIA Virtual GPU < 11.11 and Cloud Gaming < 527.27 - Unauthenticated Arbitrary File Access
CVSS 8.8
CVE-2022-31739 HIGH
Firefox < 101 and Firefox ESR < 91.10 - Path Traversal via Unescaped % Character in Download Path
CVSS 8.8
CVE-2022-23536 MEDIUM
Cortex <1.14.0 - Local File Inclusion
CVSS 6.5
CVE-2022-42893 HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42891 HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42734 HIGH
syngo Dynamics < VA40G HF01 - Path Traversal
CVSS 7.5
CVE-2022-42733 HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-42732 HIGH
syngo Dynamics < VA40G HF01 - Info Disclosure
CVSS 7.5
CVE-2022-2431 HIGH
Download Manager <= 3.2.50 - Arbitrary File Deletion via 'file[files]' Parameter
CVSS 8.1
CVE-2022-2638 MEDIUM
WordPress Plugin <4.4 - Path Traversal
CVSS 6.5
CVE-2022-32761 MEDIUM
WWBN AVideo 11.6 and dev master - Arbitrary File Read via aVideoEncoderReceiveImage
CVSS 6.5
CVE-2022-28710 MEDIUM
WWBN AVideo <11.6 - Info Disclosure
CVSS 6.5
CVE-2022-2400 MEDIUM
dompdf < 2.0.0 - Path Traversal via Untrusted File Path
CVSS 5.3
CVE-2022-34765 MEDIUM
X80 advanced RTU Communication Module - Path Traversal
CVSS 5.5
CVE-2022-24900 CRITICAL
Piano LED Visualizer < 1.3 - Path Traversal via os.path.join
CVSS 9.9
CVE-2022-20789 MEDIUM
Cisco Unified Communications Manager - Privilege Escalation
CVSS 4.9
CVE-2022-0246 MEDIUM
WordPress iQ Block Country <1.2.13 - Path Traversal
CVSS 4.9
CVE-2022-0593 MEDIUM
Login with phone number WP <1.3.7 - DoS
CVSS 6.5
Details
Vulnerabilities 519
Exploit Likelihood High