CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2021-47871 HIGH
Hestia Control Panel 1.3.2 - File Write
CVSS 8.8
CVE-2021-47746 HIGH
NodeBB Plugin Emoji 3.2.1 - Path Traversal
CVSS 7.5
CVE-2021-4472 MEDIUM
Mistral-OpenStack - Info Disclosure
CVSS 6.5
CVE-2021-4332 MEDIUM
Plus Addons for Elementor <4.1.9(pro) & 2.0.6(free) - Info Disclosure
CVSS 6.5
CVE-2021-24966 MEDIUM
Error Log Viewer <1.1.1 - Privilege Escalation
CVSS 4.9
CVE-2021-3845 HIGH
ws_scrcpy < 0.7.1 - Path Traversal
CVSS 7.5
CVE-2021-34761 MEDIUM
Cisco Firepower Threat Defense - Privilege Escalation
CVSS 4.4
CVE-2021-38477 CRITICAL
Multiple API Functions - Info Disclosure
CVSS 9.8
CVE-2021-3626 HIGH
Multipass < 1.7.0 - Unauthenticated Privilege Escalation via Localhost TCP Control Socket
CVSS 8.8
CVE-2021-1306 MEDIUM
Cisco EPN Manager, ISE, Prime Infrastructure - Path Traversal
CVSS 4.4
CVE-2021-22539 HIGH
VScode-bazel <0.4.1 - Code Injection
CVSS 8.2
CVE-2021-27250 MEDIUM
D-Link DAP-2020 v1.01rc001 - Info Disclosure
CVSS 6.5
CVE-2021-21343 MEDIUM
XStream <1.4.16 - Code Injection
CVSS 5.3
CVE-2020-37080 CRITICAL
webTareas 2.0.p8 - Privilege Escalation
CVSS 9.8
CVE-2020-37078 HIGH
i-doit Open Source CMDB 1.14.1 - File Deletion
CVSS 8.8
CVE-2020-36878 HIGH
ReQuest Serious Play Media Player 3.0 - Info Disclosure
CVE-2020-36868 HIGH
Nagios XI <5.7.3 - Privilege Escalation
CVSS 7.8
CVE-2020-36772 MEDIUM
CloudLinux CageFS <7.0.8.2 - Info Disclosure
CVSS 4.4
CVE-2020-25161 HIGH
WebAccess/SCADA <9.0 - Code Injection
CVSS 8.8
CVE-2020-2504 MEDIUM
QNAP QES < 2.1.1 - Path Traversal in File Station
CVSS 5.8
CVE-2020-26078 MEDIUM
Cisco IoT FND - Privilege Escalation
CVSS 6.5
CVE-2020-15264 HIGH
Boxstarter <2.13.0 - Code Injection
CVSS 8.0
CVE-2020-6105 HIGH
f2fs-tools < 1.14.0 - Remote Code Execution via Malicious Filesystem
CVSS 7.8
CVE-2020-8553 MEDIUM
Kubernetes ingress-nginx <0.28.0 - Privilege Escalation
CVSS 5.9
CVE-2020-5297 LOW
OctoberCMS 1.0.319-1.0.465 - Authenticated Arbitrary File Upload via Asset Manager
CVSS 3.4
Details
Vulnerabilities 519
Exploit Likelihood High