CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2021-47871
HIGH
Hestia Control Panel 1.3.2 - File Write
CVSS 8.8
CVE-2021-47746
HIGH
NodeBB Plugin Emoji 3.2.1 - Path Traversal
CVSS 7.5
CVE-2021-4472
MEDIUM
Mistral-OpenStack - Info Disclosure
CVSS 6.5
CVE-2021-4332
MEDIUM
Plus Addons for Elementor <4.1.9(pro) & 2.0.6(free) - Info Disclosure
CVSS 6.5
CVE-2021-24966
MEDIUM
Error Log Viewer <1.1.1 - Privilege Escalation
CVSS 4.9
CVE-2021-3845
HIGH
ws_scrcpy < 0.7.1 - Path Traversal
CVSS 7.5
CVE-2021-34761
MEDIUM
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 4.4
CVE-2021-38477
CRITICAL
Multiple API Functions - Info Disclosure
CVSS 9.8
CVE-2021-3626
HIGH
Multipass < 1.7.0 - Unauthenticated Privilege Escalation via Localhost TCP Control Socket
CVSS 8.8
CVE-2021-1306
MEDIUM
Cisco EPN Manager, ISE, Prime Infrastructure - Path Traversal
CVSS 4.4
CVE-2021-22539
HIGH
VScode-bazel <0.4.1 - Code Injection
CVSS 8.2
CVE-2021-27250
MEDIUM
D-Link DAP-2020 v1.01rc001 - Info Disclosure
CVSS 6.5
CVE-2021-21343
MEDIUM
XStream <1.4.16 - Code Injection
CVSS 5.3
CVE-2020-37080
CRITICAL
webTareas 2.0.p8 - Privilege Escalation
CVSS 9.8
CVE-2020-37078
HIGH
i-doit Open Source CMDB 1.14.1 - File Deletion
CVSS 8.8
CVE-2020-36878
HIGH
ReQuest Serious Play Media Player 3.0 - Info Disclosure
CVE-2020-36868
HIGH
Nagios XI <5.7.3 - Privilege Escalation
CVSS 7.8
CVE-2020-36772
MEDIUM
CloudLinux CageFS <7.0.8.2 - Info Disclosure
CVSS 4.4
CVE-2020-25161
HIGH
WebAccess/SCADA <9.0 - Code Injection
CVSS 8.8
CVE-2020-2504
MEDIUM
QNAP QES < 2.1.1 - Path Traversal in File Station
CVSS 5.8
CVE-2020-26078
MEDIUM
Cisco IoT FND - Privilege Escalation
CVSS 6.5
CVE-2020-15264
HIGH
Boxstarter <2.13.0 - Code Injection
CVSS 8.0
CVE-2020-6105
HIGH
f2fs-tools < 1.14.0 - Remote Code Execution via Malicious Filesystem
CVSS 7.8
CVE-2020-8553
MEDIUM
Kubernetes ingress-nginx <0.28.0 - Privilege Escalation
CVSS 5.9
CVE-2020-5297
LOW
OctoberCMS 1.0.319-1.0.465 - Authenticated Arbitrary File Upload via Asset Manager
CVSS 3.4
Details
Vulnerabilities
519
Exploit Likelihood
High