CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

449 vulnerabilities with CWE-73
CVE-2025-48385 HIGH
Git Bundle URI - Protocol Injection Arbitrary Code Execution
CVE-2025-49760 LOW
Microsoft Windows Storage - Spoofing via External Control of File Name or Path
CVSS 3.5
CVE-2025-49588 HIGH
Linkwarden <2.10.2 - Info Disclosure
CVE-2025-6463 HIGH
Forminator Forms < 1.44.3 - Unauthenticated Arbitrary File Deletion via Entry Upload Path Manipulation
CVSS 8.8
CVE-2025-33117 CRITICAL
IBM QRadar SIEM <7.5.0 Update Package 12 - Privilege Escalation
CVSS 9.1
CVE-2025-36506 MEDIUM
RICOH Streamline NX V3 PC Client <3.242.0 - Path Traversal
CVSS 6.5
CVE-2025-47956 MEDIUM
Windows Security App - Path Traversal
CVSS 5.5
CVE-2025-33053 HIGH KEV
CVE-2025-33053 Exploit via Malicious .URL File and WebDAV
CVSS 8.8
CVE-2025-48067 MEDIUM
OctoPrint <1.11.1 - Info Disclosure
CVSS 5.4
CVE-2025-49138 MEDIUM
HAX CMS PHP <11.0.0 - Local File Inclusion
CVSS 6.5
CVE-2025-48783 HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-48781 HIGH
Soar Cloud HRD <7.3.2025.0408 - Path Traversal
CVSS 7.5
CVE-2025-32802 MEDIUM
ISC Kea 2.4.0-2.4.1, 2.6.0-2.6.2, 2.7.0-2.7.8 - Arbitrary File Write via Configuration and API Directives
CVSS 6.1
CVE-2025-4603 CRITICAL
eMagicOne Store Manager - Path Traversal
CVSS 9.1
CVE-2025-4602 MEDIUM
eMagicOne Store Manager for WooCommerce <1.2.5 - Info Disclosure
CVSS 5.9
CVE-2025-2409 CRITICAL
ABB ASPECT-Enterprise NEXUS Series MATRIX Series <= 3.08.03 - Authenticated Arbitrary File Write
CVSS 9.1
CVE-2025-3812 HIGH
WPBot Pro Wordpress Chatbot <13.6.2 - Privilege Escalation
CVSS 8.1
CVE-2025-26646 HIGH
Microsoft .NET, Visual Studio, and Build Tools - Path Spoofing via External Control of File Name or Path
CVSS 8.0
CVE-2025-26684 MEDIUM
Microsoft Defender for Endpoint - Privilege Escalation
CVSS 6.7
CVE-2025-3419 HIGH
Eventin plugin <4.0.26 - Info Disclosure
CVSS 7.5
CVE-2025-46762 HIGH
Apache Parquet < 1.15.2 - Remote Code Execution via Parquet-Avro Schema Parsing
CVSS 8.1
CVE-2025-1056 MEDIUM
AXIS Camera Station Pro < 6.8.43213 - Authenticated Arbitrary File Write via File Modification
CVSS 6.1
CVE-2025-43951 CRITICAL
LabVantage <8.8.0.13 HF6 - Path Traversal
CVSS 9.8
CVE-2025-3103 HIGH
CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - ...
CVSS 7.5
CVE-2025-29709 CRITICAL
SourceCodester Company Website CMS 1.0 - File Upload
CVSS 9.8
Details
Vulnerabilities 449
Exploit Likelihood High