Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient saf
Windows HTML Platforms Security Feature Bypass Vulnerability
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar
A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Se
Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded S
An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15f
paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.
Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboa
A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerabili
There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthen
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected
Aimeos is an Open Source e-commerce framework for online shops. Starting in version 2024.01.1 and prior to version 2024.
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fail
Microsoft Outlook Remote Code Execution Vulnerability
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of W
Windows Compressed Folder Tampering Vulnerability
An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is us
NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system fi
The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are
Windows Compressed Folder Tampering Vulnerability
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path
NTLM Hash Disclosure Spoofing Vulnerability
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects
External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local
A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerabi
A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This a
A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some u
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbi
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions.
A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by
A vulnerability, which was classified as critical, has been found in SourceCodester Insurance Management System 1.0. Thi
A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue af
Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Pla
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Softwar
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and inclu
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started