VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 8 of 29
  • CVE-2026-32204HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2026-5054HigApr 11, 2026
    risk 0.51cvss 7.8epss 0.00

    NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2026-24287HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62842HigJan 2, 2026
    risk 0.51cvss 7.8epss 0.00

    An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the…

  • CVE-2025-59516HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59511HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.

  • CVE-2020-36868HigOct 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of attacker-controlled inputs,…

  • CVE-2025-55316HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-6463HigJul 2, 2025
    risk 0.51cvss 8.8epss 0.12

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and including, 1.44.2. This makes…

  • CVE-2024-4230HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in…

  • CVE-2024-41183HigOct 22, 2024
    risk 0.51cvss 7.8epss 0.01

    Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevation of privileges.

  • CVE-2024-20366HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability exists…

  • CVE-2023-5247HigNov 30, 2023
    risk 0.51cvss 7.8epss 0.00

    Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which…

  • CVE-2023-21566HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Visual Studio Elevation of Privilege Vulnerability

  • CVE-2023-21800HigFeb 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2020-6105HigOct 15, 2020
    risk 0.51cvss 7.8epss 0.02

    An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2020-1984HigApr 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable. This issue affects…

  • CVE-2026-18127HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.00

    External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.

  • CVE-2026-15307HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a…

  • CVE-2026-66310HigAug 4, 2026
    risk 0.50cvss 7.7epss 0.00

    External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.