Skip to content
Noroxi

CWE-641 · 13 records

Improper Restriction of Names for Files and Other Resources

CVEs in this class

13 records

  • yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)

    CriticalCVSS 9.6No exploitEPSS 1%

    yt-dlp project · yt-dlpJun 23, 2026

  • Active Directory Domain Services Elevation of Privilege Vulnerability

    HighCVSS 8.8Proof of conceptEPSS 1%

    microsoft · windows 10 1607Mar 10, 2026

  • Microsoft Office Remote Code Execution Vulnerability

    HighCVSS 8.4No exploitEPSS 1%

    microsoft · 365 appsJun 10, 2025

  • Microsoft Outlook Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 1%

    microsoft · officeJan 14, 2025

  • Microsoft Office OneNote Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 1%

    microsoft · officeJan 14, 2025

  • Microsoft Office Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 1%

    microsoft · 365 appsJun 10, 2025

  • GitHub Copilot Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    microsoft · github copilotJul 14, 2026

  • CVE-2023-0046
    28Monitor

    Improper Restriction of Names for Files and Other Resources in lirantal/daloradius

    HighCVSS 7.2No exploitEPSS 1%

    daloradius · daloradiusJan 4, 2023

  • Luminance Studio 2.17 Denial of Service via Malformed Input

    MediumCVSS 6.9No exploitEPSS 0%

    pixarra · luminance studioMar 23, 2026

  • Windows Distributed File System (DFS) Remote Code Execution Vulnerability

    MediumCVSS 6.7No exploitEPSS 1%

    microsoft · windows 10 1507Jun 11, 2024

  • 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation all

    MediumCVSS 6.5No exploitEPSS 0%

    axis communications ab · axis osMar 4, 2025

  • File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access dif

    MediumCVSS 5.4No exploitEPSS 1%

    bosch · bf-osAug 1, 2022

  • Cisco Identity Services Engine Authenticated Write Vulnerability

    MediumCVSS 4.9No exploitEPSS 1%

    cisco · cisco identity services engine softwareSep 16, 2026

All vulnerability classes