Skip to content
Noroxi

CWE-73 · 573 records

External Control of File Name or Path

CVEs in this class

575 records

  • Internet Shortcut Files Remote Code Execution Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 87%

    microsoft · windows 10 1507Jun 10, 2025

  • NTLM Hash Disclosure Spoofing Vulnerability

    MediumCVSS 6.5KEVWeaponizedEPSS 84%

    microsoft · windows 10 1507Nov 12, 2024

  • CVE-2022-39952
    69This week

    A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,

    CriticalCVSS 9.8WeaponizedEPSS 100%

    fortinet · fortinacFeb 16, 2023

  • CVE-2025-24054
    69This week

    NTLM Hash Disclosure Spoofing Vulnerability

    MediumCVSS 5.4KEVWeaponizedEPSS 59%

    microsoft · windows 10 1507Mar 11, 2025

  • CVE-2024-8517
    67This week

    SPIP Bigup Multipart File Upload OS Command Injection

    CriticalCVSS 9.8WeaponizedEPSS 95%

    spip · spipSep 6, 2024

  • CVE-2023-4634
    65This week

    Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution

    CriticalCVSS 9.8Proof of conceptEPSS 86%

    davidlingren · media library assistantSep 6, 2023

  • CVE-2018-17246
    64This week

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.

    CriticalCVSS 9.8Proof of conceptEPSS 82%

    elastic · kibanaDec 20, 2018

  • CVE-2023-3643
    62This week

    Boss Mini document file inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 75%

    carel · boss mini firmwareJul 12, 2023

  • PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface

    HighCVSS 7.1KEVWeaponizedEPSS 2%

    paloaltonetworks · pan-osFeb 12, 2025

  • This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc0

    MediumCVSS 6.5No exploitEPSS 67%

    dlink · dap-2020 firmwareApr 14, 2021

  • XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights

    HighCVSS 7.5No exploitEPSS 47%

    xstream · xstreamMar 22, 2021

  • GLPI allows remote code execution through the plugin loader

    HighCVSS 8.8No exploitEPSS 21%

    glpi-project · glpiJul 10, 2024

  • SourceCodester Clinic Queuing System GET Parameter index.php file inclusion

    HighCVSS 8.8No exploitEPSS 21%

    oretnom23 · clinic queuing systemJan 7, 2024

  • NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.

    HighCVSS 8.8No exploitEPSS 20%

    nvidia · triton inference serverMay 14, 2024

  • Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store API

    CriticalCVSS 10.0Proof of conceptEPSS 1%

    flowiseai · flowiseJun 25, 2026

  • SUNNET Corporate Training Management System - External Control of File Name or Path

    CriticalCVSS 10.0No exploitEPSS 1%

    sun.net · ehrd ctmsAug 30, 2025

  • Cisco Crosswork Security Hardening Release: August 2026

    CriticalCVSS 10.0No exploitEPSS 0%

    cisco · cisco crosswork planningAug 19, 2026

  • CVE-2025-6463
    39Monitor

    Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submiss

    HighCVSS 8.8No exploitEPSS 13%

    incsub · forminatorJul 2, 2025

  • CVE-2019-3681
    39Monitor

    osc: stores downloaded (supposed) RPM in network-controlled filesystem paths

    CriticalCVSS 9.8No exploitEPSS 1%

    suse · linux enterprise serverJun 29, 2020

  • GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle

    CriticalCVSS 9.8No exploitEPSS 1%

    rurban · gdJun 14, 2026

  • CVE-2023-2152
    39Monitor

    SourceCodester Student Study Center Desk Management System index.php file inclusion

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · student study center desk management systemApr 18, 2023

  • There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipul

    CriticalCVSS 9.8No exploitEPSS 1%

    auvesy · versiondogOct 22, 2021

  • CVE-2020-9752
    39Monitor

    Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through i

    CriticalCVSS 9.8No exploitEPSS 1%

    naver · cloud explorerMar 22, 2020

  • A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb.

    CriticalCVSS 9.8No exploitEPSS 1%

    wwbn · avideoJan 10, 2024

  • CVE-2023-4749
    39Monitor

    SourceCodester Inventory Management System index.php file inclusion

    CriticalCVSS 9.8No exploitEPSS 1%

    mayurik · inventory management systemSep 3, 2023

All vulnerability classes