CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2026-30905 HIGH
Zoom Communications Zoom Workplace Vdi Plugin < 6.6.11 - External Control of File Name or Path
CVSS 7.8
CVE-2026-0259 HIGH
Palo Alto WildFire WF-500/WF-500-B - Arbitrary File Read/Delete
CVSS 8.8
CVE-2026-43891 HIGH
changedetection.io: Arbitrary Local File Read via crafted backup restore
CVSS 7.5
CVE-2026-41107 HIGH
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVSS 7.4
CVE-2026-41088 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-40421 MEDIUM
Microsoft Word Information Disclosure Vulnerability
CVSS 4.3
CVE-2026-40370 HIGH
Microsoft SQL Server - File Path Control Remote Code Execution
CVSS 8.8
CVE-2026-32204 HIGH
Azure Monitor Agent Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-43989 HIGH
JunoClaw: upload_wasm accepted arbitrary filesystem paths without validation
CVSS 8.5
CVE-2026-8043 CRITICAL
Ivanti Xtraction < 2026.2 - Authenticated Path Traversal and Arbitrary File Write
CVSS 9.6
CVE-2026-42866 MEDIUM
Tookie: Arbitrary file write via path traversal in -u username / -U userfile output filename
CVE-2026-42845 HIGH
Grav: Anonymous Page Content Overwrite via Form File Upload filename Override
CVE-2026-41693 HIGH
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
CVSS 8.2
CVE-2026-44127 HIGH
SEPPmail Secure Email Gateway - Local File Inclusion (LFI) and Arbitrary File Deletion
CVE-2026-7633 MEDIUM
Totolink N300RH cstecgi.cgi setUploadSetting file inclusion
CVSS 6.5
CVE-2026-30893 CRITICAL
Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer
CVSS 9.0
CVE-2026-42424 MEDIUM
OpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA Paths
CVSS 5.7
CVE-2026-41177 MEDIUM
Squidex has Blind SSRF via file:// Protocol in Restore API leading to Local File Interaction
CVSS 5.5
CVE-2026-4132 HIGH
HTTP Headers <= 1.19.2 - Authenticated Remote Code Execution via htpasswd Path Manipulation
CVSS 7.2
CVE-2026-39378 MEDIUM
nbconvert 6.5-7.17.0 HTMLExporter Image Embedding - Arbitrary File Read
CVSS 6.5
CVE-2026-39377 MEDIUM
nbconvert 6.5-7.17.0 Cell Attachments - Arbitrary File Write
CVSS 6.5
CVE-2026-41389 MEDIUM
OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths
CVSS 5.8
CVE-2026-35465 HIGH
SecureDrop Client has path injection in read_gzip_header_filename()
CVSS 7.5
CVE-2026-40342 CRITICAL
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
CVSS 9.9
CVE-2026-35032 HIGH
Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner
CVSS 8.1
Details
Vulnerabilities 519
Exploit Likelihood High