CWE-73
407 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 2 of 9
- CVE-2022-2638MEDIUMCVSS 6.5EG 6.52022-08-29
The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server
- CVE-2022-28710MEDIUMCVSS 6.5EG 6.52022-08-22
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to tri…
- CVE-2022-31739HIGHCVSS 8.8EG 8.82022-12-22
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Fir…
- CVE-2022-32761MEDIUMCVSS 6.5EG 6.52022-08-22
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTT…
- CVE-2022-34669HIGHCVSS 8.8EG 7.82022-12-30
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code executi…
- CVE-2022-34765MEDIUMCVSS 5.5EG 5.32022-07-13
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (…
- CVE-2022-39952CRITICALCVSS 9.8EG 9.82023-02-16
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated …
- CVE-2022-42732HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any f…
- CVE-2022-42733HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any f…
- CVE-2022-42734HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder acc…
- CVE-2022-42891HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder acc…
- CVE-2022-42893HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder acc…
- CVE-2022-43513HIGHCVSS 8.2EG 7.52023-01-10
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename…
- CVE-2022-45213MEDIUMCVSS 5.3EG 9.82023-01-01
perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.
- CVE-2022-4983MEDIUMCVSS 6.9EG 0.02025-11-12
TEC-IT TBarCode version 11.15 contains a vulnerability in the TBarCode11.ocx ActiveX/OCX control's licensing handling (INI-file based) that can be abused to cause remote creation of files on the host filesystem. Depending on where files ca…
- CVE-2023-0003MEDIUMCVSS 6.5EG 6.52023-02-08
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
- CVE-2023-0008MEDIUMCVSS 4.4EG 4.42023-05-10
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
- CVE-2023-1070HIGHCVSS 7.1EG 7.12023-02-27
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
- CVE-2023-1105HIGHCVSS 8.1EG 8.12023-03-01
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
- CVE-2023-20114MEDIUMCVSS 6.5EG 6.52023-11-01
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of inpu…
- CVE-2023-20234MEDIUMCVSS 4.4EG 4.42023-08-23
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because ther…
- CVE-2023-2152MEDIUMCVSS 5.3EG 5.32023-04-18
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument…
- CVE-2023-21566HIGHCVSS 7.8EG 7.82023-02-14
Visual Studio Elevation of Privilege Vulnerability
- CVE-2023-21800HIGHCVSS 7.8EG 7.82023-02-14
Windows Installer Elevation of Privilege Vulnerability
- CVE-2023-2554HIGHCVSS 7.2EG 7.22023-05-05
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
- CVE-2023-26282MEDIUMCVSS 4.2EG 4.22024-03-05
IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the system to modify files or data on the system. IBM X-Force ID: 248415.
- CVE-2023-28603HIGHCVSS 7.7EG 7.72023-06-13
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
- CVE-2023-29324MEDIUMCVSS 6.5EG 6.52023-05-09
Windows MSHTML Platform Security Feature Bypass Vulnerability
- CVE-2023-30943MEDIUMCVSS 6.5EG 6.52023-05-02
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the sy…
- CVE-2023-3256HIGHCVSS 8.8EG 8.82023-06-22
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.
- CVE-2023-32615MEDIUMCVSS 6.5EG 6.52023-09-05
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attac…
- CVE-2023-34982MEDIUMCVSS 5.5EG 5.52023-11-15
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.…
- CVE-2023-35308MEDIUMCVSS 6.5EG 6.52023-07-11
Windows MSHTML Platform Security Feature Bypass Vulnerability
- CVE-2023-35384MEDIUMCVSS 5.4EG 5.42023-08-08
Windows HTML Platforms Security Feature Bypass Vulnerability
- CVE-2023-35985HIGHCVSS 8.8EG 8.82023-11-27
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitra…
- CVE-2023-36019CRITICALCVSS 9.6EG 9.62023-12-12
Microsoft Power Platform Connector Spoofing Vulnerability
- CVE-2023-3643HIGHCVSS 7.3EG 7.32023-07-12
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to i…
- CVE-2023-36634HIGHCVSS 7.1EG 7.12023-09-13
An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to…
- CVE-2023-36764HIGHCVSS 8.8EG 8.82023-09-12
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2023-39542HIGHCVSS 8.8EG 8.82023-11-27
A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user in…
- CVE-2023-40194HIGHCVSS 8.8EG 8.82023-11-27
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, w…
- CVE-2023-4191MEDIUMCVSS 6.3EG 6.32023-08-06
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument page leads to f…
- CVE-2023-43074MEDIUMCVSS 5.2EG 5.22023-10-23
Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.
- CVE-2023-45588HIGHCVSS 8.2EG 8.22025-03-14
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configu…
- CVE-2023-4634CRITICALCVSS 9.8EG 9.82023-09-06
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_f…
- CVE-2023-46851MEDIUMCVSS 4.9EG 4.92023-11-07
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them. Exposing internal files then …
- CVE-2023-47147MEDIUMCVSS 5.9EG 5.92024-03-15
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.
- CVE-2023-47171MEDIUMCVSS 6.5EG 6.52024-01-10
An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
- CVE-2023-4749MEDIUMCVSS 6.3EG 6.32023-09-04
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file inclusion. It is pos…
- CVE-2023-47862CRITICALCVSS 9.8EG 9.82024-01-10
A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HT…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →