The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Direct
A vulnerability classified as problematic was found in ForU CMS up to 2020-06-23. Affected by this vulnerability is an u
CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allo
Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can r
Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when resto
A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue aff
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affec
IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the sy
A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the funct
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie
A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file th
Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Incl
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in vers
Microsoft Power Platform Connector Spoofing Vulnerability
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.
Microsoft SharePoint Server Elevation of Privilege Vulnerability
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due
A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted mal
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All
External Control of File Name or Path in h2oai/h2o-3
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
Windows Installer Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA E
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may pote
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown par
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user wit
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to cr
Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenti
A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of t
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affec
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges t
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. A
Windows HTML Platforms Security Feature Bypass Vulnerability
perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as criti
Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially
A vulnerability, which was classified as problematic, has been found in sternenseemann sternenblog. This issue affects t
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrato
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started