← Back
CWE-73

514 CVEs • Abstraction: Base • Likelihood of Exploit: High

External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.

JSON object

Loading...

CVEs (514)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Davidlingren
1Media Library Assistant
Jun 17, 2026
Sep 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied t...Show more
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.Show less
1Openautomationsoftware
1Oas Platform
Jun 17, 2026
Sep 5, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or...Show more
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1Mayurik
1Inventory Management System
Jun 17, 2026
Sep 4, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file i...Show more
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238638 is the identifier assigned to this vulnerability.Show less
1Cisco
1Firepower Extensible Operating System
Jun 17, 2026
Aug 23, 2023
N/A· v4
6.0 MEDIUM· v3
N/A· v2
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability...Show more
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because there is no validation of parameters when a specific CLI command is used. An attacker could exploit this vulnerability by authenticating to an affected device and using the command at the CLI. A successful exploit could allow the attacker to overwrite any file on the disk of the affected device, including system files. The attacker must have valid administrative credentials on the affected device to exploit this vulnerability.Show less
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows HTML Platforms Security Feature Bypass Vulnerability
1Resort Reservation System Project
1Resort Reservation System
Jun 17, 2026
Aug 6, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argum...Show more
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-236234 is the identifier assigned to this vulnerability.Show less
1Carel
1Boss Mini Firmware
Jun 17, 2026
Jul 12, 2023
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion....Show more
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.Show less
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows MSHTML Platform Security Feature Bypass Vulnerability
1Advantech
1R Seenet
Jun 17, 2026
Jun 22, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.
1Zoom
1Virtual Desktop Infrastructure
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
May 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
May 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows MSHTML Platform Security Feature Bypass Vulnerability
1Bumsys Project
1Bumsys
Jun 17, 2026
May 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
May 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrar...Show more
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.Show less
1Oretnom23
1Student Study Center Desk Management System
Jun 17, 2026
Apr 18, 2023
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulat...Show more
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability.Show less
1Posimyth
1The Plus Addons For Elementor
Jun 17, 2026
Mar 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor create...Show more
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file_get_contents with no verification that the file being supplied was an SVG file, so any user with access to the Elementor page builder, such as contributors, could read arbitrary files on the WordPress installation.Show less
1Flatpress
1Flatpress
Jun 17, 2026
Mar 1, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
1Teampass
1Teampass
Jun 17, 2026
Feb 27, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
1Fortinet
1Fortinac
Jun 17, 2026
Feb 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow...Show more
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.Show less
1Microsoft
3Visual Studio 2017
Visual Studio 2019Visual Studio 2022
Jun 17, 2026
Feb 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Visual Studio Elevation of Privilege Vulnerability