CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

449 vulnerabilities with CWE-73
CVE-2026-28459 HIGH
OpenClaw <2026.2.12 - Path Traversal
CVSS 7.1
CVE-2026-28442 HIGH
ZimaOS 1.5.2-beta3 - Unauthenticated Arbitrary File Deletion via API Path Parameter Manipulation
CVSS 8.5
CVE-2026-28286 HIGH
ZimaOS 1.5.2-beta3 - Unauthenticated Path Traversal and Arbitrary File Write via API Request
CVSS 8.5
CVE-2026-26228 MEDIUM
VLC for Android <3.7.0 - Path Traversal
CVSS 4.9
CVE-2026-23521 MEDIUM
Traccar <= 6.11.1 - Authenticated Path Traversal and Arbitrary File Write via Device uniqueId
CVSS 6.5
CVE-2026-27211 CRITICAL
Cloud Hypervisor 34.0-50.0 - Info Disclosure
CVSS 10.0
CVE-2026-27115 HIGH
ADB Explorer <=0.9.26020 - Arbitrary File Deletion
CVSS 7.1
CVE-2026-26975 HIGH
Music Assistant Server < 2.7.0 - Unauthenticated Remote Code Execution via Playlist Update API
CVSS 8.8
CVE-2026-27008 MEDIUM
OpenClaw <2026.2.15 - Path Traversal
CVSS 6.7
CVE-2026-26202 HIGH
Penpot < 2.13.2 - Authenticated Arbitrary File Read via Font Variant RPC Endpoint
CVSS 7.5
CVE-2026-26361 MEDIUM
Dell Unisphere for PowerMax 10.2 - Path Traversal
CVSS 6.5
CVE-2026-26360 HIGH
Dell Unisphere for PowerMax 10.2 - Path Traversal
CVSS 8.1
CVE-2026-26359 HIGH
Dell Unisphere for PowerMax 10.2 - Path Traversal
CVSS 8.8
CVE-2026-25964 MEDIUM
Tandoor Recipes <2.5.1 - Path Traversal
CVSS 4.9
CVE-2026-1669 HIGH
Keras 3.0.0-3.13.1 - Arbitrary File Read via HDF5 External Dataset References
CVSS 7.5
CVE-2026-26158 HIGH
Red Hat Enterprise Linux 6 - Path Traversal via Malicious Tar Archive Extraction
CVSS 7.0
CVE-2026-26157 HIGH
Red Hat Enterprise Linux 6 - Path Traversal and Arbitrary File Write via BusyBox Archive Extraction
CVSS 7.0
CVE-2026-21249 LOW
Windows 10/11 Unauthenticated Spoofing via NTLM File Path Control
CVSS 3.3
CVE-2026-25636 HIGH
calibre < 9.2.0 - Path Traversal and Arbitrary File Write via EPUB Conversion
CVSS 8.2
CVE-2026-25628 HIGH
Qdrant 1.9.3-1.15.6 - Arbitrary File Write via Logger Endpoint
CVSS 8.5
CVE-2026-23835 MEDIUM
LobeHub < 1.143.3 - Arbitrary File Write and Denial of Service via File Upload Request Manipulation
CVE-2026-23529 HIGH
Kafka Connect BigQuery Connector <2.11.0 - Info Disclosure
CVSS 7.7
CVE-2026-20931 HIGH
Windows Telephony Service - Privilege Escalation
CVSS 8.0
CVE-2026-20925 MEDIUM
Windows 10/11, Server 2008/2012/2016 Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2026-20872 MEDIUM
Windows 10/11, Server 2008/2012/2016 Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
Details
Vulnerabilities 449
Exploit Likelihood High