CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
396 vulnerabilities with CWE-73
CVE-2026-5210
HIGH
SourceCodester Leave Application System file inclusion
CVSS 7.3
CVE-2026-30282
CRITICAL
Cast to TV Screen Mirroring 2.2.77 - File Overwrite
CVSS 9.0
CVE-2026-30284
HIGH
UXGROUP Voice Recorder 10.0 - File Overwrite
CVSS 8.6
CVE-2026-30281
CRITICAL
MaruNuri LLC v2.0.23 - Arbitrary File Overwrite
CVSS 9.8
CVE-2026-30276
CRITICAL
DeftPDF Document Translator 54.0 - File Overwrite
CVSS 9.8
CVE-2026-30940
HIGH
baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE
CVSS 7.2
CVE-2026-33027
MEDIUM
Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory
CVSS 6.5
CVE-2026-33989
HIGH
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
CVSS 8.1
CVE-2026-33645
HIGH
Fireshare has Path Traversal Arbitrary File Write in `/api/uploadChunked`
CVSS 7.1
CVE-2026-0965
LOW
Libssh: libssh: denial of service via improper configuration file handling
CVSS 3.3
CVE-2026-33329
HIGH
FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle
CVSS 8.1
CVE-2026-33309
CRITICAL
Langflow has an Arbitrary File Write (RCE) via v2 API
CVSS 9.9
CVE-2026-33354
HIGH
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
CVSS 7.6
CVE-2026-2351
MEDIUM
Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Read
CVSS 6.5
CVE-2026-33476
HIGH
SiYuan has an Unauthenticated Arbitrary File Read via Path Traversal
CVSS 7.5
CVE-2026-32949
HIGH
SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL
CVE-2026-32749
HIGH
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
CVSS 7.6
CVE-2026-30903
CRITICAL
Zoom Workplace <6.6.0 - Privilege Escalation
CVSS 9.6
CVE-2026-27825
CRITICAL
MCP Atlassian <0.17.0 - Path Traversal
CVSS 9.0
CVE-2026-25605
MEDIUM
SICAM SIAPP SDK <V2.1.7 - Path Traversal
CVSS 6.7
CVE-2026-25573
HIGH
SICAM SIAPP SDK <V2.1.7 - Command Injection
CVSS 7.4
CVE-2026-24287
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2026-30240
CRITICAL
Budibase <=3.31.5 - Path Traversal
CVSS 9.6
CVE-2026-29611
HIGH
OpenClaw <2026.2.14 - Path Traversal
CVSS 7.5
CVE-2026-28459
HIGH
OpenClaw <2026.2.12 - Path Traversal
CVSS 7.1
Details
Vulnerabilities
396
Exploit Likelihood
High