CWE-73 · 572 записей
External Control of File Name or Path
CVE этого класса
573 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
91Срочно | CVE-2025-33053Готовый эксплойт | Internet Shortcut Files Remote Code Execution Vulnerabilitymicrosoft · windows 10 1507 · CWE-73 | Высокая8,8 | KEV | 87,0 % | 10 июн. 2025 г. |
81Срочно | CVE-2024-43451Готовый эксплойт | NTLM Hash Disclosure Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-73 | Средняя6,5 | KEV | 84,1 % | 12 нояб. 2024 г. |
69На этой неделе | CVE-2022-39952Готовый эксплойт | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,fortinet · fortinac · CWE-73 | Критическая9,8 | — | 99,8 % | 16 февр. 2023 г. |
69На этой неделе | CVE-2025-24054Готовый эксплойт | NTLM Hash Disclosure Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-73 | Средняя5,4 | KEV | 58,9 % | 11 мар. 2025 г. |
67На этой неделе | CVE-2024-8517Готовый эксплойт | SPIP Bigup Multipart File Upload OS Command Injectionspip · spip · CWE-73 | Критическая9,8 | — | 94,6 % | 6 сент. 2024 г. |
65На этой неделе | CVE-2023-4634Proof of concept | Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Executiondavidlingren · media library assistant · CWE-73 | Критическая9,8 | — | 85,6 % | 6 сент. 2023 г. |
64На этой неделе | CVE-2018-17246Proof of concept | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.elastic · kibana · CWE-73 | Критическая9,8 | — | 82,3 % | 20 дек. 2018 г. |
62На этой неделе | CVE-2023-3643Proof of concept | Boss Mini document file inclusioncarel · boss mini firmware · CWE-73 | Критическая9,8 | — | 75,4 % | 12 июл. 2023 г. |
59В плане | CVE-2025-0111Готовый эксплойт | PAN-OS: Authenticated File Read Vulnerability in the Management Web Interfacepaloaltonetworks · pan-os · CWE-73 | Высокая7,1 | KEV | 2,0 % | 12 февр. 2025 г. |
46В плане | CVE-2021-27250Эксплойта нет | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc0dlink · dap-2020 firmware · CWE-73 | Средняя6,5 | — | 67,4 % | 14 апр. 2021 г. |
44В плане | CVE-2021-21343Эксплойта нет | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rightsxstream · xstream · CWE-73 | Высокая7,5 | — | 46,7 % | 22 мар. 2021 г. |
41В плане | CVE-2024-37149Эксплойта нет | GLPI allows remote code execution through the plugin loaderglpi-project · glpi · CWE-73 | Высокая8,8 | — | 21,1 % | 10 июл. 2024 г. |
41В плане | CVE-2024-0265Эксплойта нет | SourceCodester Clinic Queuing System GET Parameter index.php file inclusionoretnom23 · clinic queuing system · CWE-73 | Высокая8,8 | — | 20,9 % | 7 янв. 2024 г. |
41В плане | CVE-2024-0087Эксплойта нет | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.nvidia · triton inference server · CWE-73 | Высокая8,8 | — | 19,9 % | 14 мая 2024 г. |
40В плане | CVE-2025-71338Proof of concept | Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store APIflowiseai · flowise · CWE-73 | Критическая10,0 | — | 1,2 % | 25 июн. 2026 г. |
40В плане | CVE-2025-54945Эксплойта нет | SUNNET Corporate Training Management System - External Control of File Name or Pathsun.net · ehrd ctms · CWE-73 | Критическая10,0 | — | 0,5 % | 30 авг. 2025 г. |
40В плане | CVE-2026-20358Эксплойта нет | Cisco Crosswork Security Hardening Release: August 2026cisco · cisco crosswork planning · CWE-73 | Критическая10,0 | — | 0,5 % | 19 авг. 2026 г. |
39Наблюдать | CVE-2025-6463Эксплойта нет | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submissincsub · forminator · CWE-73 | Высокая8,8 | — | 12,7 % | 2 июл. 2025 г. |
39Наблюдать | CVE-2019-3681Эксплойта нет | osc: stores downloaded (supposed) RPM in network-controlled filesystem pathssuse · linux enterprise server · CWE-73 | Критическая9,8 | — | 1,4 % | 29 июн. 2020 г. |
39Наблюдать | CVE-2026-11526Эксплойта нет | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandlerurban · gd · CWE-73 | Критическая9,8 | — | 1,4 % | 14 июн. 2026 г. |
39Наблюдать | CVE-2023-2152Эксплойта нет | SourceCodester Student Study Center Desk Management System index.php file inclusionoretnom23 · student study center desk management system · CWE-73 | Критическая9,8 | — | 1,2 % | 18 апр. 2023 г. |
39Наблюдать | CVE-2021-38477Эксплойта нет | There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulauvesy · versiondog · CWE-73 | Критическая9,8 | — | 1,2 % | 22 окт. 2021 г. |
39Наблюдать | CVE-2020-9752Эксплойта нет | Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through inaver · cloud explorer · CWE-73 | Критическая9,8 | — | 1,1 % | 22 мар. 2020 г. |
39Наблюдать | CVE-2023-47862Эксплойта нет | A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb.wwbn · avideo · CWE-73 | Критическая9,8 | — | 1,1 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-4749Эксплойта нет | SourceCodester Inventory Management System index.php file inclusionmayurik · inventory management system · CWE-73 | Критическая9,8 | — | 1,0 % | 3 сент. 2023 г. |
- CVE-2025-3305391Срочно
Internet Shortcut Files Remote Code Execution Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 87 %microsoft · windows 10 150710 июн. 2025 г.
- CVE-2024-4345181Срочно
NTLM Hash Disclosure Spoofing Vulnerability
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 84 %microsoft · windows 10 150712 нояб. 2024 г.
- CVE-2022-3995269На этой неделе
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,
КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %fortinet · fortinac16 февр. 2023 г.
- CVE-2025-2405469На этой неделе
NTLM Hash Disclosure Spoofing Vulnerability
СредняяCVSS 5,4KEVГотовый эксплойтEPSS 59 %microsoft · windows 10 150711 мар. 2025 г.
- CVE-2024-851767На этой неделе
SPIP Bigup Multipart File Upload OS Command Injection
КритическаяCVSS 9,8Готовый эксплойтEPSS 95 %spip · spip6 сент. 2024 г.
- CVE-2023-463465На этой неделе
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
КритическаяCVSS 9,8Proof of conceptEPSS 86 %davidlingren · media library assistant6 сент. 2023 г.
- CVE-2018-1724664На этой неделе
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.
КритическаяCVSS 9,8Proof of conceptEPSS 82 %elastic · kibana20 дек. 2018 г.
- CVE-2023-364362На этой неделе
Boss Mini document file inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 75 %carel · boss mini firmware12 июл. 2023 г.
- CVE-2025-011159В плане
PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
ВысокаяCVSS 7,1KEVГотовый эксплойтEPSS 2 %paloaltonetworks · pan-os12 февр. 2025 г.
- CVE-2021-2725046В плане
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc0
СредняяCVSS 6,5Эксплойта нетEPSS 67 %dlink · dap-2020 firmware14 апр. 2021 г.
- CVE-2021-2134344В плане
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
ВысокаяCVSS 7,5Эксплойта нетEPSS 47 %xstream · xstream22 мар. 2021 г.
- CVE-2024-3714941В плане
GLPI allows remote code execution through the plugin loader
ВысокаяCVSS 8,8Эксплойта нетEPSS 21 %glpi-project · glpi10 июл. 2024 г.
- CVE-2024-026541В плане
SourceCodester Clinic Queuing System GET Parameter index.php file inclusion
ВысокаяCVSS 8,8Эксплойта нетEPSS 21 %oretnom23 · clinic queuing system7 янв. 2024 г.
- CVE-2024-008741В плане
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.
ВысокаяCVSS 8,8Эксплойта нетEPSS 20 %nvidia · triton inference server14 мая 2024 г.
- CVE-2025-7133840В плане
Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store API
КритическаяCVSS 10,0Proof of conceptEPSS 1 %flowiseai · flowise25 июн. 2026 г.
- CVE-2025-5494540В плане
SUNNET Corporate Training Management System - External Control of File Name or Path
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %sun.net · ehrd ctms30 авг. 2025 г.
- CVE-2026-2035840В плане
Cisco Crosswork Security Hardening Release: August 2026
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %cisco · cisco crosswork planning19 авг. 2026 г.
- CVE-2025-646339Наблюдать
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submiss
ВысокаяCVSS 8,8Эксплойта нетEPSS 13 %incsub · forminator2 июл. 2025 г.
- CVE-2019-368139Наблюдать
osc: stores downloaded (supposed) RPM in network-controlled filesystem paths
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %suse · linux enterprise server29 июн. 2020 г.
- CVE-2026-1152639Наблюдать
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rurban · gd14 июн. 2026 г.
- CVE-2023-215239Наблюдать
SourceCodester Student Study Center Desk Management System index.php file inclusion
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · student study center desk management system18 апр. 2023 г.
- CVE-2021-3847739Наблюдать
There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipul
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %auvesy · versiondog22 окт. 2021 г.
- CVE-2020-975239Наблюдать
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through i
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %naver · cloud explorer22 мар. 2020 г.
- CVE-2023-4786239Наблюдать
A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wwbn · avideo10 янв. 2024 г.
- CVE-2023-474939Наблюдать
SourceCodester Inventory Management System index.php file inclusion
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mayurik · inventory management system3 сент. 2023 г.