The product allows user input to control or influence paths or file names that are used in filesystem operations.
Volume of CVEs assigned to CWE-73 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
513 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-33053HIGH External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | Jun 10, 2025 | 8.8 | 96 | YES | YES |
CVE-2024-43451MEDIUM NTLM Hash Disclosure Spoofing Vulnerability | Nov 12, 2024 | 6.5 | 92 | YES | NO |
CVE-2022-39952CRITICAL A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6. | Feb 16, 2023 | 9.8 | 92 | NO | YES |
CVE-2024-8517CRITICAL SPIP before 4.3.2, 4.2.16, and
4.1.18 is vulnerable to a command injection issue. A
remote and unauthenticated attacker can execute arbitrary operating system commands by sending | Sep 6, 2024 | 9.8 | 91 | NO | YES |
CVE-2025-24054MEDIUM External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Mar 11, 2025 | 5.4 | 90 | YES | YES |
CVE-2023-4634CRITICAL The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient | Sep 6, 2023 | 9.8 | 88 | NO | YES |
CVE-2023-3643CRITICAL A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the | Jul 12, 2023 | 9.8 | 85 | NO | YES |
CVE-2018-17246CRITICAL Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that | Dec 20, 2018 | 9.8 | 83 | NO | YES |
CVE-2020-1631CRITICAL A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning | May 4, 2020 | 9.8 | 72 | YES | NO |
CVE-2025-0111MEDIUM An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read fil | Feb 12, 2025 | 6.5 | 62 | YES | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.