Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-73

91
CRITICAL
250
HIGH
193
MEDIUM
18
LOW
598 CVEs · Page 11/12
4.9
CVE-2024-12875

The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Direct

4.7
CVE-2024-0728

A vulnerability classified as problematic was found in ForU CMS up to 2020-06-23. Affected by this vulnerability is an u

4.4
CVE-2020-36772

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allo

4.4
CVE-2024-27175

Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can r

4.4
CVE-2024-39303

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when resto

4.3
CVE-2024-2155

A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue aff

4.3
CVE-2024-12357

A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affec

4.2
CVE-2023-26282

IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the sy

2.7
CVE-2024-6937

A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the funct

2.7
CVE-2024-10672

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie

2.7
CVE-2024-10492

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file th

CVE-2024-9575

Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Incl

9.8
CVE-2022-39952

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8

9.8
CVE-2023-4634

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers

9.6
CVE-2023-36019

Microsoft Power Platform Connector Spoofing Vulnerability

8.8
CVE-2023-3256

Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

8.8
CVE-2023-36764

Microsoft SharePoint Server Elevation of Privilege Vulnerability

8.8
CVE-2023-35985

An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due

8.8
CVE-2023-39542

A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted mal

8.8
CVE-2023-40194

An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due

8.2
CVE-2022-43513

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All

8.2
CVE-2023-6569

External Control of File Name or Path in h2oai/h2o-3

8.1
CVE-2023-1105

External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.

7.8
CVE-2023-21800

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2023-21566

Visual Studio Elevation of Privilege Vulnerability

7.8
CVE-2023-5247

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA E

7.7
CVE-2023-28603

Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may pote

7.3
CVE-2023-3643

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown par

7.2
CVE-2023-2554

External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

7.1
CVE-2023-1070

External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

7.1
CVE-2023-36634

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr

6.5
CVE-2023-0003

A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user wit

6.5
CVE-2021-4332

The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin

6.5
CVE-2023-30943

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to cr

6.5
CVE-2023-29324

Windows MSHTML Platform Security Feature Bypass Vulnerability

6.5
CVE-2023-35308

Windows MSHTML Platform Security Feature Bypass Vulnerability

6.5
CVE-2023-32615

A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform

6.5
CVE-2023-20114

A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenti

6.3
CVE-2014-125044

A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of t

6.3
CVE-2023-4191

A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affec

6.3
CVE-2023-4749

A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected

5.5
CVE-2023-34982

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges t

5.5
CVE-2023-6618

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. A

5.4
CVE-2023-35384

Windows HTML Platforms Security Feature Bypass Vulnerability

5.3
CVE-2022-45213

perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.

5.3
CVE-2023-2152

A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as criti

5.2
CVE-2023-43074

Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially

5.0
CVE-2014-125059

A vulnerability, which was classified as problematic, has been found in sternenseemann sternenblog. This issue affects t

4.9
CVE-2023-46851

Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrato

4.4
CVE-2023-0008

A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator

Frequently Asked Questions

What is CWE-73?

CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-73?

There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.

How can I protect against CWE-73 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.

Detect CWE-73 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.

Get Started