CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2026-26360 HIGH
Dell Unisphere for PowerMax 10.2 - Path Traversal
CVSS 8.1
CVE-2026-26359 HIGH
Dell Unisphere for PowerMax 10.2 - Path Traversal
CVSS 8.8
CVE-2026-24708 HIGH
OpenStack Nova <30.2.2 - Memory Corruption
CVSS 8.2
CVE-2026-25964 MEDIUM
Tandoor Recipes <2.5.1 - Path Traversal
CVSS 4.9
CVE-2026-1669 HIGH
Keras 3.0.0-3.13.1 - Arbitrary File Read via HDF5 External Dataset References
CVSS 7.5
CVE-2026-26158 HIGH
Red Hat Enterprise Linux 6 - Path Traversal via Malicious Tar Archive Extraction
CVSS 7.0
CVE-2026-26157 HIGH
Red Hat Enterprise Linux 6 - Path Traversal and Arbitrary File Write via BusyBox Archive Extraction
CVSS 7.0
CVE-2026-21249 LOW
Windows 10/11 Unauthenticated Spoofing via NTLM File Path Control
CVSS 3.3
CVE-2026-25636 HIGH
calibre < 9.2.0 - Path Traversal and Arbitrary File Write via EPUB Conversion
CVSS 8.2
CVE-2026-25628 HIGH
Qdrant 1.9.3-1.15.6 - Arbitrary File Write via Logger Endpoint
CVSS 8.5
CVE-2026-23835 MEDIUM
LobeHub < 1.143.3 - Arbitrary File Write and Denial of Service via File Upload Request Manipulation
CVE-2026-23529 HIGH
Kafka Connect BigQuery Connector <2.11.0 - Info Disclosure
CVSS 7.7
CVE-2026-20931 HIGH
Windows Telephony Service - Privilege Escalation
CVSS 8.0
CVE-2026-20925 MEDIUM
Windows 10/11, Server 2008/2012/2016 Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2026-20872 MEDIUM
Windows 10/11, Server 2008/2012/2016 Unauthenticated Spoofing via NTLM File Path Control
CVSS 6.5
CVE-2026-22783 CRITICAL
Iris <2.4.24 - Privilege Escalation
CVSS 9.6
CVE-2025-71338 CRITICAL
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
CVSS 10.0
CVE-2025-71334 CRITICAL
Flowise - Arbitrary File Access via Missing Chat Flow ID Validation
CVSS 9.8
CVE-2025-71333 CRITICAL
Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint
CVSS 9.8
CVE-2025-71324 HIGH
Flowise - Arbitrary File Read via chatId Parameter
CVSS 7.5
CVE-2025-52465 HIGH
GeoServer < 2.26.4 and 2.27.0-2.27.2 - Authenticated Arbitrary File Write
CVSS 7.2
CVE-2025-12656 LOW
Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion
CVSS 3.8
CVE-2025-0898 MEDIUM
Xpro Elementor Addons - Pro <= 1.4.7 - Authenticated (Contributor+) Arbitrary File Read via Draw SVG
CVSS 6.5
CVE-2025-65115 HIGH
Hitachi JP1 IT Desktop Management and JP1 NETM DM - Remote Code Execution
CVSS 8.8
CVE-2025-61879 HIGH
Infoblox NIOS <9.0.7 - Privilege Escalation
CVSS 7.7
Details
Vulnerabilities 519
Exploit Likelihood High