LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allow
A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file del
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnera
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete
eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file
In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion.
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extr
The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat
File corruption vulnerabilities in ASPECT provide attackers access to overwrite sys-tem files if session administrator c
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that wo
The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuffi
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attac
Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Tran
Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm
An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attac
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary
Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authentica
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly d
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.
In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target s
eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/up
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNM
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute ar
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion d
The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion du
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion d
The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized att
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The s
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locall
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *
The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2
Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Clie
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate'
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated a
The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started