The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to a
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi
exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate
The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authen
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured im
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell co
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf
In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated ag
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2
3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse th
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path t
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can
ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument t
OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli
Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerabilit
NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. Th
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patch
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in th
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, Dire
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized u
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craf
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction di
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by us
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly saniti
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetD
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started