The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in
The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vu
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary fil
An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Ma
An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Mana
Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file servi
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all ver
The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads i
@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include
HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.
Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version
Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Nam
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including,
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil
External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: U
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to
Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (L
NTLM Hash Disclosure Spoofing Vulnerability
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker wit
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount f
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mi
The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includi
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticate
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n
A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which hav
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could
The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in
The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' featur
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedP
A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init
A vulnerability was found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this
A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown functi
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose i
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. M
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior
A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an unknown part of the fi
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started