CWE-73
628 CVEs • Abstraction: Base • Likelihood of Exploit: High
External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
CVEs (628)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Mar 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Mar 11, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it possible for authenticated attackers, with s...Show more |
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by readin...Show more |
The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This makes it possible for authenticated...Show more |
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive informa...Show more |
HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php. |
1Pebbletemplates 2Pebble Pebble TemplatesJun 17, 2026 Feb 27, 2025 4.8 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafti...Show more |
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize...Show more |
1Ibm 1Watson Query With Cloud Pak For Data Jun 17, 2026 Feb 22, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due...Show more |
1Ivanti 2Connect Secure Policy SecureJun 17, 2026 Feb 21, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files. |
1Synology 1Active Backup For Business Agent Jun 17, 2026 Feb 13, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 a...Show more |
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are rea...Show more |
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as...Show more |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Feb 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NTLM Hash Disclosure Spoofing Vulnerability |
1Ivanti 2Connect Secure Policy SecureJun 17, 2026 Feb 11, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files. |
Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device's filesystem. |
1Codedropz 1Drag And Drop Multiple File Upload Contact Form 7 Jun 17, 2026 Jan 31, 2025 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all...Show more |
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2s_view_log' AJAX action. This makes it possible for authenticate...Show more |
A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations. |