CWE-73
628 CVEs • Abstraction: Base • Likelihood of Exploit: High
External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
CVEs (628)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Oretnom23 1Clinic Queuing System Jun 17, 2026 Jan 7, 2024 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component GET Parameter Handler. The manipula...Show more |
External Control of File Name or Path in h2oai/h2o-3 |
1Microsoft 2Azure Logic Apps Power PlatformJun 17, 2026 Dec 12, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 Microsoft Power Platform Connector Spoofing Vulnerability |
1Oretnom23 1Simple Student Attendance System Jun 17, 2026 Dec 8, 2023 N/A· v4 8.8 HIGH· v3 5.2 MEDIUM· v2 A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of...Show more |
1Mitsubishielectric 4Gx Works3 Melsoft Iq AppportalMelsoft Navigator+1 moreJun 17, 2026 Nov 30, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legit...Show more |
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arb...Show more |
A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs t...Show more |
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can crea...Show more |
1Aveva 13Batch Management Communication DriversEdge+10 moreJun 17, 2026 Nov 15, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in...Show more |
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them. Exposing in...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Nov 1, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is du...Show more |
1Dell 3Unity Operating Environment Unity Xt Operating EnvironmentUnityvsa Operating EnvironmentJun 17, 2026 Oct 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.
|
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authen...Show more |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
1Davidlingren 1Media Library Assistant Jun 17, 2026 Sep 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied t...Show more |
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or...Show more |
1Mayurik 1Inventory Management System Jun 17, 2026 Sep 4, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file i...Show more |
1Cisco 1Firepower Extensible Operating System Jun 17, 2026 Aug 23, 2023 N/A· v4 6.0 MEDIUM· v3 N/A· v2 A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability...Show more |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreAug 10, 2026 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows HTML Platforms Security Feature Bypass Vulnerability |
1Resort Reservation System Project 1Resort Reservation System Jun 17, 2026 Aug 6, 2023 N/A· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argum...Show more |