Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-73

91
CRITICAL
250
HIGH
193
MEDIUM
18
LOW
598 CVEs · Page 8/12
7.5
CVE-2025-3431

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in

7.5
CVE-2025-3103

The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vu

7.5
CVE-2025-3419

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary fil

7.5
CVE-2025-48781

An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Ma

7.5
CVE-2025-48783

An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Mana

7.5
CVE-2025-59049

Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file servi

7.5
CVE-2025-8422

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all ver

7.5
CVE-2025-11451

The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads i

7.5
CVE-2025-68155

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find

7.3
CVE-2025-9529

A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include

7.2
CVE-2025-25761

HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.

7.2
CVE-2024-1243

Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the

7.1
CVE-2025-68478

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p

6.8
CVE-2024-12058

External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version

6.8
CVE-2025-1686

Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Nam

6.8
CVE-2025-13320

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including,

6.7
CVE-2025-26684

External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil

6.7
CVE-2025-20614

External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: U

6.5
CVE-2024-12861

The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to

6.5
CVE-2025-0630

Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (L

6.5
CVE-2025-21377

NTLM Hash Disclosure Spoofing Vulnerability

6.5
CVE-2025-0111 KEV

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker wit

6.5
CVE-2024-47265

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount f

6.5
CVE-2025-25478

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mi

6.5
CVE-2025-1730

The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includi

6.5
CVE-2025-24054 KEV

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network

6.5
CVE-2025-24996

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network

6.5
CVE-2024-51553

Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator

6.5
CVE-2025-49138

HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticate

6.5
CVE-2025-36506

External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an

6.5
CVE-2025-20269

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri

6.5
CVE-2025-59185

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n

6.5
CVE-2025-59244

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n

6.5
CVE-2025-59483

A validation vulnerability exists in an undisclosed URL in the Configuration utility.  Note: Software versions which hav

6.5
CVE-2025-8048

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a

6.5
CVE-2025-8050

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.  The vulnerability could

6.5
CVE-2025-13380

The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in

6.5
CVE-2021-4472

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' featur

6.4
CVE-2025-35053

Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedP

6.4
CVE-2025-12915

A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init

6.3
CVE-2025-0211

A vulnerability was found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this

6.3
CVE-2025-2982

A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown functi

6.2
CVE-2025-29819

External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose i

6.1
CVE-2025-1056

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the

6.1
CVE-2025-32802

Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. M

5.9
CVE-2025-4602

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u

5.8
CVE-2025-64714

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior

5.5
CVE-2025-0202

A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an unknown part of the fi

5.5
CVE-2025-47956

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

5.5
CVE-2025-53769

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

Frequently Asked Questions

What is CWE-73?

CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-73?

There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.

How can I protect against CWE-73 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.

Detect CWE-73 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.

Get Started