Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-73

91
CRITICAL
250
HIGH
193
MEDIUM
18
LOW
598 CVEs · Page 4/12
7.5
CVE-2026-6101

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to a

7.5
CVE-2026-49145

App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th

7.5
CVE-2026-56452

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser

7.5
CVE-2026-18048

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f

7.5
CVE-2026-74884

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi

7.5
CVE-2026-78208

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate

7.5
CVE-2026-19913

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation

7.5
CVE-2026-16444

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authen

7.5
CVE-2026-19084

The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured im

7.4
CVE-2026-25573

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell co

7.4
CVE-2026-41107

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf

7.4
CVE-2026-10303

In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated ag

7.4
CVE-2026-65802

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat

7.3
CVE-2026-5210

A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a

7.3
CVE-2026-10694

A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i

7.3
CVE-2026-19009

A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core

7.2
CVE-2026-30940

baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme

7.2
CVE-2026-23898

Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

7.2
CVE-2026-4132

The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec

7.2
CVE-2025-52465

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2

7.2
CVE-2026-55477

3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse th

7.2
CVE-2026-16137

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path t

7.2
CVE-2026-16139

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can

7.1
CVE-2026-27115

ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument t

7.1
CVE-2026-28459

OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli

7.1
CVE-2026-33645

Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerabilit

7.1
CVE-2026-5053

NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers

7.1
CVE-2026-5809

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. Th

7.1
CVE-2026-44641

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma

7.1
CVE-2026-53915

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

7.1
CVE-2026-55700

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro

7.1
CVE-2026-47214

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos

7.1
CVE-2026-59194

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patch

7.1
CVE-2026-59196

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste

7.1
CVE-2026-46336

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on

7.1
CVE-2026-58484

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`

7.1
CVE-2026-65896

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in th

7.1
CVE-2026-18806

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im

7.1
CVE-2026-75830

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability

7.1
CVE-2026-48798

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, Dire

7.1
CVE-2026-55527

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized u

7.1
CVE-2026-55609

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear

7.0
CVE-2026-26157

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craf

7.0
CVE-2026-26158

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction di

7.0
CVE-2026-81726

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by us

6.8
CVE-2026-35593

Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled

6.8
CVE-2026-59807

Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex

6.8
CVE-2026-65939

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb

6.8
CVE-2026-12513

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly saniti

6.7
CVE-2026-27008

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetD

Frequently Asked Questions

What is CWE-73?

CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-73?

There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.

How can I protect against CWE-73 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.

Detect CWE-73 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.

Get Started