Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Volume of CVEs assigned to CWE-377 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
97 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40973HIGH A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `tru | Apr 28, 2026 | 7.0 | 35 | NO | NO |
CVE-2026-44878HIGH A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful | Jul 21, 2026 | 7.2 | 31 | NO | NO |
CVE-2011-4119CRITICAL caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install. | Oct 26, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-46406MEDIUM Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without | Jun 29, 2026 | 6.1 | 30 | NO | NO |
CVE-2018-25068CRITICAL A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fil | Jan 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2012-2666CRITICAL golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script. | Jul 9, 2021 | 9.8 | 30 | NO | NO |
CVE-2025-67223HIGH The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, wh | Apr 28, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-20204HIGH In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.5, 10.2.2510.9, 10.1.2507.19, 10.0.2503.13, | Apr 15, 2026 | 7.1 | 28 | NO | NO |
CVE-2013-4561CRITICAL In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity. | Jun 30, 2022 | 9.1 | 28 | NO | NO |
CVE-2026-62294MEDIUM Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creatin | Jul 15, 2026 | 5.1 | 27 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.