Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferr
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the Live
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion i
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4.
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, w
Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection,
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 un
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-downlo
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges o
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attac
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attack
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due t
Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to
In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mech
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.ph
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loa
NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supp
Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst
IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfig
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Se
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se
changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by
HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-suppli
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R
Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management I
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started