CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

396 vulnerabilities with CWE-73
CVE-2025-3431 HIGH
ZoomSounds - WordPress Wave Audio Player with Playlist <6.91 - Info...
CVSS 7.5
CVE-2025-2004 CRITICAL
Simple WP Events <1.8.17 - Path Traversal
CVSS 9.1
CVE-2025-3033 HIGH
Firefox < 137 - Info Disclosure
CVSS 7.7
CVE-2025-2982 MEDIUM
Legrand SMS PowerView 1.x - File Inclusion
CVSS 6.3
CVE-2025-1911 LOW
Product Import Export for WooCommerce - Product CSV Suite <2.5.0 - ...
CVSS 2.7
CVE-2025-27147 HIGH
GLPI Inventory Plugin <1.5.0 - Privilege Escalation
CVSS 8.2
CVE-2025-1972 LOW
WordPress <2.6.2 - Privilege Escalation
CVSS 2.7
CVE-2025-0452 HIGH
eosphoros-ai/DB-GPT - Privilege Escalation
CVSS 8.2
CVE-2025-29930 MEDIUM
imFAQ <1.0.1 - Local File Inclusion
CVE-2025-24996 MEDIUM
Windows NTLM - Path Traversal
CVSS 6.5
CVE-2025-24054 MEDIUM KEV
Windows NTLM - Path Traversal
CVSS 6.5
CVE-2025-1730 MEDIUM
Simple Download Counter <2.0 - Info Disclosure
CVSS 6.5
CVE-2025-25478 MEDIUM
Syspass 3.2.x - Info Disclosure
CVSS 6.5
CVE-2025-25761 HIGH
HkCms <2.3.2.240702 - Code Injection
CVSS 7.2
CVE-2025-1686 MEDIUM
io.pebbletemplates:pebble - Path Traversal
CVSS 6.8
CVE-2025-27137 MEDIUM
Dependency-Track <4.12.6 - Code Injection
CVSS 4.4
CVE-2025-0111 MEDIUM KEV
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 6.5
CVE-2025-0109 MEDIUM
Palo Alto Networks PAN-OS - Unauthenticated File Deletion
CVE-2025-21377 MEDIUM
NTLM Hash Disclosure Spoofing - Info Disclosure
CVSS 6.5
CVE-2025-0630 MEDIUM
Western Telematic - Local File Inclusion
CVSS 6.5
CVE-2025-0851 CRITICAL
Ai.djl API < 0.31.1 - Path Traversal
CVSS 9.8
CVE-2025-0105 CRITICAL
Palo Alto Networks Expedition - Info Disclosure
CVSS 9.1
CVE-2025-0211 MEDIUM
Campcodes School Faculty Scheduling System 1.0 - File Inclusion
CVSS 6.3
CVE-2025-0202 MEDIUM
TCS BaNCS 10 - File Inclusion
CVSS 5.5
CVE-2024-5986 CRITICAL
Ai.h2o H2o-core - Remote Code Execution
CVSS 9.1
Details
Vulnerabilities 396
Exploit Likelihood High