CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
449 vulnerabilities with CWE-73
CVE-2025-48385
HIGH
Git Bundle URI - Protocol Injection Arbitrary Code Execution
CVE-2025-49760
LOW
Microsoft Windows Storage - Spoofing via External Control of File Name or Path
CVSS 3.5
CVE-2025-49588
HIGH
Linkwarden <2.10.2 - Info Disclosure
CVE-2025-6463
HIGH
Forminator Forms < 1.44.3 - Unauthenticated Arbitrary File Deletion via Entry Upload Path Manipulation
CVSS 8.8
CVE-2025-33117
CRITICAL
IBM QRadar SIEM <7.5.0 Update Package 12 - Privilege Escalation
CVSS 9.1
CVE-2025-36506
MEDIUM
RICOH Streamline NX V3 PC Client <3.242.0 - Path Traversal
CVSS 6.5
CVE-2025-47956
MEDIUM
Windows Security App - Path Traversal
CVSS 5.5
CVE-2025-33053
HIGH
KEV
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
CVSS 8.8
CVE-2025-48067
MEDIUM
OctoPrint <1.11.1 - Info Disclosure
CVSS 5.4
CVE-2025-49138
MEDIUM
HAX CMS PHP <11.0.0 - Local File Inclusion
CVSS 6.5
CVE-2025-48783
HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-48781
HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-32802
MEDIUM
ISC Kea 2.4.0-2.4.1, 2.6.0-2.6.2, 2.7.0-2.7.8 - Arbitrary File Write via Configuration and API Directives
CVSS 6.1
CVE-2025-4603
CRITICAL
eMagicOne Store Manager - Path Traversal
CVSS 9.1
CVE-2025-4602
MEDIUM
eMagicOne Store Manager for WooCommerce <1.2.5 - Info Disclosure
CVSS 5.9
CVE-2025-2409
CRITICAL
ABB ASPECT-Enterprise NEXUS Series MATRIX Series <= 3.08.03 - Authenticated Arbitrary File Write
CVSS 9.1
CVE-2025-3812
HIGH
WPBot Pro Wordpress Chatbot <13.6.2 - Privilege Escalation
CVSS 8.1
CVE-2025-26646
HIGH
Microsoft .NET, Visual Studio, and Build Tools - Path Spoofing via External Control of File Name or Path
CVSS 8.0
CVE-2025-26684
MEDIUM
Microsoft Defender for Endpoint - Privilege Escalation
CVSS 6.7
CVE-2025-3419
HIGH
Eventin plugin <4.0.26 - Info Disclosure
CVSS 7.5
CVE-2025-46762
HIGH
Apache Parquet < 1.15.2 - Remote Code Execution via Parquet-Avro Schema Parsing
CVSS 8.1
CVE-2025-1056
MEDIUM
AXIS Camera Station Pro < 6.8.43213 - Authenticated Arbitrary File Write via File Modification
CVSS 6.1
CVE-2025-43951
CRITICAL
LabVantage <8.8.0.13 HF6 - Path Traversal
CVSS 9.8
CVE-2025-3103
HIGH
CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - ...
CVSS 7.5
CVE-2025-29709
CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
Details
Vulnerabilities
449
Exploit Likelihood
High