CWE-641 · 13 records
Improper Restriction of Names for Files and Other Resources
CVEs in this class
13 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2026-50023No exploit | yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)yt-dlp project · yt-dlp · CWE-641 | Critical9.6 | — | 0.7% | Jun 23, 2026 |
35Monitor | CVE-2026-25177Proof of concept | Active Directory Domain Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-641 | High8.8 | — | 1.3% | Mar 10, 2026 |
33Monitor | CVE-2025-47953No exploit | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-641 | High8.4 | — | 0.5% | Jun 10, 2025 |
31Monitor | CVE-2025-21361No exploit | Microsoft Outlook Remote Code Execution Vulnerabilitymicrosoft · office · CWE-641 | High7.8 | — | 0.7% | Jan 14, 2025 |
31Monitor | CVE-2025-21402No exploit | Microsoft Office OneNote Remote Code Execution Vulnerabilitymicrosoft · office · CWE-641 | High7.8 | — | 0.7% | Jan 14, 2025 |
31Monitor | CVE-2025-47173No exploit | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-641 | High7.8 | — | 0.6% | Jun 10, 2025 |
31Monitor | CVE-2026-50510No exploit | GitHub Copilot Remote Code Execution Vulnerabilitymicrosoft · github copilot · CWE-641 | High7.8 | — | 0.4% | Jul 14, 2026 |
28Monitor | CVE-2023-0046No exploit | Improper Restriction of Names for Files and Other Resources in lirantal/daloradiusdaloradius · daloradius · CWE-641 | High7.2 | — | 1.0% | Jan 4, 2023 |
27Monitor | CVE-2019-25623No exploit | Luminance Studio 2.17 Denial of Service via Malformed Inputpixarra · luminance studio · CWE-641 | Medium6.9 | — | 0.2% | Mar 23, 2026 |
26Monitor | CVE-2024-30063No exploit | Windows Distributed File System (DFS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-641 | Medium6.7 | — | 1.0% | Jun 11, 2024 |
26Monitor | CVE-2024-47260No exploit | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allaxis communications ab · axis os · CWE-641 | Medium6.5 | — | 0.4% | Mar 4, 2025 |
21Monitor | CVE-2022-36302No exploit | File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access difbosch · bf-os · CWE-641 | Medium5.4 | — | 0.6% | Aug 1, 2022 |
19Monitor | CVE-2026-20282No exploit | Cisco Identity Services Engine Authenticated Write Vulnerabilitycisco · cisco identity services engine software · CWE-641 | Medium4.9 | — | 0.6% | Sep 16, 2026 |
- CVE-2026-5002338Monitor
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
CriticalCVSS 9.6No exploitEPSS 1%yt-dlp project · yt-dlpJun 23, 2026
- CVE-2026-2517735Monitor
Active Directory Domain Services Elevation of Privilege Vulnerability
HighCVSS 8.8Proof of conceptEPSS 1%microsoft · windows 10 1607Mar 10, 2026
- CVE-2025-4795333Monitor
Microsoft Office Remote Code Execution Vulnerability
HighCVSS 8.4No exploitEPSS 1%microsoft · 365 appsJun 10, 2025
- CVE-2025-2136131Monitor
Microsoft Outlook Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 1%microsoft · officeJan 14, 2025
- CVE-2025-2140231Monitor
Microsoft Office OneNote Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 1%microsoft · officeJan 14, 2025
- CVE-2025-4717331Monitor
Microsoft Office Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 1%microsoft · 365 appsJun 10, 2025
- CVE-2026-5051031Monitor
GitHub Copilot Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%microsoft · github copilotJul 14, 2026
- CVE-2023-004628Monitor
Improper Restriction of Names for Files and Other Resources in lirantal/daloradius
HighCVSS 7.2No exploitEPSS 1%daloradius · daloradiusJan 4, 2023
- CVE-2019-2562327Monitor
Luminance Studio 2.17 Denial of Service via Malformed Input
MediumCVSS 6.9No exploitEPSS 0%pixarra · luminance studioMar 23, 2026
- CVE-2024-3006326Monitor
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
MediumCVSS 6.7No exploitEPSS 1%microsoft · windows 10 1507Jun 11, 2024
- CVE-2024-4726026Monitor
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation all
MediumCVSS 6.5No exploitEPSS 0%axis communications ab · axis osMar 4, 2025
- CVE-2022-3630221Monitor
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access dif
MediumCVSS 5.4No exploitEPSS 1%bosch · bf-osAug 1, 2022
- CVE-2026-2028219Monitor
Cisco Identity Services Engine Authenticated Write Vulnerability
MediumCVSS 4.9No exploitEPSS 1%cisco · cisco identity services engine softwareSep 16, 2026