Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-73

91
CRITICAL
250
HIGH
193
MEDIUM
18
LOW
598 CVEs · Page 6/12
5.3
CVE-2026-82637

browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing atta

5.0
CVE-2026-19353

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the fi

4.9
CVE-2025-54162

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator a

4.9
CVE-2026-25964

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a P

4.9
CVE-2026-26228

VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server rout

4.9
CVE-2026-41412

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio

4.9
CVE-2026-59819

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's

4.7
CVE-2026-3602

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1

4.3
CVE-2026-40421

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose

4.3
CVE-2026-15540

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function

3.8
CVE-2025-12656

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory de

3.3
CVE-2026-21249

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

3.3
CVE-2026-0965

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker c

3.1
CVE-2026-15921

Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.

3.0
CVE-2026-49358

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene

CVE-2025-66003

An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via s

CVE-2026-23835

LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Ba

CVE-2026-44127

SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the iden

CVE-2026-42845

The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-con

CVE-2026-42866

Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write

CVE-2026-42881

STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve l

CVE-2026-40605

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal

CVE-2026-46399

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0

CVE-2026-34030

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code wh

CVE-2026-53632

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP

CVE-2026-8921

External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co

CVE-2026-53648

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product fi

CVE-2026-13014

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute

CVE-2026-8920

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wa

CVE-2026-9587

An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file

CVE-2026-50162

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a le

CVE-2026-47425

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `Entry

CVE-2026-57916

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare ar

CVE-2026-12070

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email,

CVE-2026-54200

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax,

CVE-2026-45725

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compl

CVE-2026-34492

External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue

CVE-2026-18751

External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App:

CVE-2026-52875

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-sc

CVE-2026-76158

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v

CVE-2026-54134

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custo

CVE-2026-49360

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server dep

CVE-2026-77139

The extension fails to validate a client-supplied template element key before using it to build file paths for saving an

CVE-2026-62865

Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integrati

CVE-2026-79653

In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage

9.8
CVE-2025-0851

A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad act

9.8
CVE-2024-55371

Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to res

9.8
CVE-2024-55372

Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to

9.8
CVE-2025-29708

SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Se

9.8
CVE-2025-29709

SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfo

Frequently Asked Questions

What is CWE-73?

CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-73?

There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.

How can I protect against CWE-73 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.

Detect CWE-73 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.

Get Started