A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overw
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. V
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly bein
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.
ws-scrcpy is vulnerable to External Control of File Name or Path
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or a
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and de
The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex ve
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware i
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high p
The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functio
A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified C
There are multiple API function codes that permit reading and writing data to or from files and directories, which could
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket t
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel a
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Eng
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwri
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH enviro
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create fol
An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A
A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, S
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an au
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator
A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attack
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and t
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP h
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started