CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2025-54162
MEDIUM
QNAP File Station 5.5.6.4691-5.5.6.5067 - Authenticated Path Traversal
CVSS 4.9
CVE-2025-64712
CRITICAL
unstructured < 0.18.18 - Path Traversal and Arbitrary File Write via MSG Attachment Processing
CVSS 9.8
CVE-2025-53912
CRITICAL
MedDream PACS Premium <7.3.6.870 - Info Disclosure
CVSS 9.6
CVE-2025-66292
HIGH
DPanel < 1.9.2 - Authenticated Arbitrary File Deletion via Path Traversal
CVSS 8.1
CVE-2025-66003
HIGH
smb4k < 4.0.5 - Local Privilege Escalation via Samba Share Path Control
CVE-2025-14059
MEDIUM
EmailKit plugin <1.6.1 - Path Traversal
CVSS 6.5
CVE-2025-68428
HIGH
jsPDF < 4.0.0 - Path Traversal via loadFile Method
CVSS 7.5
CVE-2025-62842
HIGH
HBS 3 Hybrid Backup Sync <26.2.0.938 - Path Traversal
CVSS 7.8
CVE-2025-12654
LOW
WPvivid Backup & Migration <0.9.120 - Path Traversal
CVSS 2.7
CVE-2025-68478
HIGH
langflow < 1.7.0 - Arbitrary File Write via Unrestricted fs_path Parameter
CVSS 7.1
CVE-2025-68155
HIGH
@vitejs/plugin-rs <0.5.8 - Info Disclosure
CVSS 7.5
CVE-2025-66449
HIGH
ConvertX < 0.16.0 - Authenticated Arbitrary File Write via Upload Endpoint
CVSS 8.8
CVE-2025-13320
MEDIUM
WP User Manager <2.9.12 - Privilege Escalation
CVSS 6.8
CVE-2025-65473
CRITICAL
easyimages2.0 < 2.8.6 - Authenticated Arbitrary File Rename via /admin/filer.php
CVSS 9.1
CVE-2025-67461
MEDIUM
Zoom Rooms for macOS <6.6.0 - Info Disclosure
CVSS 5.0
CVE-2025-59516
HIGH
Windows Storage VSP Driver - Privilege Escalation
CVSS 7.8
CVE-2025-65799
MEDIUM
usememos memos <0.25.2 - Path Traversal
CVSS 4.3
CVE-2025-12529
HIGH
WordPress Cost Calculator Builder <3.6.3 - RCE
CVSS 8.8
CVE-2025-66257
CRITICAL
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter - Pat...
CVSS 9.1
CVE-2025-66254
CRITICAL
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter - Una...
CVSS 9.1
CVE-2025-13380
MEDIUM
AI Engine for WordPress: ChatGPT - Arbitrary File Read
CVSS 6.5
CVE-2025-30201
HIGH
Wazuh <4.13.0 - Privilege Escalation
CVSS 7.7
CVE-2025-11973
MEDIUM
简数采集器 WordPress Plugin <=2.6.3 - Info Disclosure
CVSS 4.9
CVE-2025-13322
HIGH
WP AUDIO GALLERY <2.0 - Privilege Escalation
CVSS 8.1
CVE-2025-64714
MEDIUM
PrivateBin 1.7.7-2.0.3 - Unauthenticated Local File Inclusion via Template Cookie
CVSS 5.8
Details
Vulnerabilities
519
Exploit Likelihood
High