OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file del
IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and includ
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user
External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to co
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Re
The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to e
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacke
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a networ
auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import
It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and i
The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins
The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitr
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory cr
Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary fil
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unau
imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] param
An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an
Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-
: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This i
Foxit PDF Reader < 4.3.1.0218 exposes a JavaScript API function, createDataObject(), that allows untrusted PDF content
dpanel is an open source server management panel written in Go. In versions 1.2.0 through 1.7.2, dpanel allows authentic
QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the
aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings
calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary ass
TEC-IT TBarCode version 11.15 contains a vulnerability in the TBarCode11.ocx ActiveX/OCX control's licensing handling (I
ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed throug
A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacke
External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Com
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability t
External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocument
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an a
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitr
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and
VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an atta
The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable t
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate th
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.
Frequently Asked Questions
What is CWE-73?
CWE-73 (CWE-73) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-73?
There are 605 CVE records associated with CWE-73 in our database. Of these, 91 are critical severity, 250 are high severity, and 193 are medium severity.
How can I protect against CWE-73 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-73 using AI-powered security agents.
Detect CWE-73 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-73 vulnerabilities across your infrastructure.
Get Started