CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2026-33329 HIGH
FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle
CVSS 8.1
CVE-2026-33309 CRITICAL
Langflow 1.2.0-1.8.1 v2 File Upload - Arbitrary File Write
CVSS 9.9
CVE-2026-33354 HIGH
AVideo <=26.0 aVideoEncoder chunkFile - Local File Read
CVSS 7.6
CVE-2026-2351 MEDIUM
Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Read
CVSS 6.5
CVE-2026-33476 HIGH
SiYuan <3.6.2 appearance Filepath - Arbitrary File Read
CVSS 7.5
CVE-2026-32949 HIGH
SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL
CVSS 7.5
CVE-2026-32749 HIGH
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
CVSS 7.6
CVE-2026-30903 CRITICAL
Zoom Workplace <6.6.0 - Privilege Escalation
CVSS 9.6
CVE-2026-27825 CRITICAL
MCP Atlassian <0.17.0 - Path Traversal
CVSS 9.0
CVE-2026-25605 MEDIUM
SICAM SIAPP SDK <V2.1.7 - Path Traversal
CVSS 6.7
CVE-2026-25573 HIGH
SICAM SIAPP SDK <V2.1.7 - Command Injection
CVSS 7.4
CVE-2026-24287 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2026-30240 CRITICAL
Budibase < 3.31.5 - Authenticated Path Traversal via PWA ZIP Processing Endpoint
CVSS 9.6
CVE-2026-29611 HIGH
OpenClaw <2026.2.14 - Path Traversal
CVSS 7.5
CVE-2026-28459 HIGH
OpenClaw <2026.2.12 - Path Traversal
CVSS 7.1
CVE-2026-28442 HIGH
ZimaOS 1.5.2-beta3 - Unauthenticated Arbitrary File Deletion via API Path Parameter Manipulation
CVSS 8.5
CVE-2026-28286 HIGH
ZimaOS 1.5.2-beta3 - Unauthenticated Path Traversal and Arbitrary File Write via API Request
CVSS 8.5
CVE-2026-26228 MEDIUM
VLC for Android <3.7.0 - Path Traversal
CVSS 4.9
CVE-2026-23521 MEDIUM
Traccar <= 6.11.1 - Authenticated Path Traversal and Arbitrary File Write via Device uniqueId
CVSS 6.5
CVE-2026-27211 CRITICAL
Cloud Hypervisor 34.0-50.0 - Info Disclosure
CVSS 10.0
CVE-2026-27115 HIGH
ADB Explorer <=0.9.26020 - Arbitrary File Deletion
CVSS 7.1
CVE-2026-26975 HIGH
Music Assistant Server < 2.7.0 - Unauthenticated Remote Code Execution via Playlist Update API
CVSS 8.8
CVE-2026-27008 MEDIUM
OpenClaw <2026.2.15 - Path Traversal
CVSS 6.7
CVE-2026-26202 HIGH
Penpot < 2.13.2 - Authenticated Arbitrary File Read via Font Variant RPC Endpoint
CVSS 7.5
CVE-2026-26361 MEDIUM
Dell Unisphere for PowerMax 10.2 - Path Traversal
CVSS 6.5
Details
Vulnerabilities 519
Exploit Likelihood High