Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauth
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypas
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the exte
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload wor
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated user
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access b
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used t
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance b
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vuln
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadat
webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows aut
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical in
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper co
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control o
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding.
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated a
The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A s
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path
External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauth
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate prof
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the
A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the admin
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string arg
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated us
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 an
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper
Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 299 CVE records associated with CWE-73 in our database. Of these, 53 are critical severity, 142 are high severity, and 65 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started