CWE-73: CWE-73

148
Total CVEs
26
Critical
72
High
7.5
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
24
2025
75
2024
32
2023
14
2022
1

Top Affected Vendors

1 Microsoft 21
2 Zoom 4
3 Fortinet 3
4 Siemens 2
5 Scshr 2
6 Opentext 2
7 Paloaltonetworks 2
8 Dell 2
9 H2o 2
10 Ivanti 2

All CWE-73 CVEs (148)

CVE-2024-12058
6.8

This vulnerability allows remote authenticated attackers with admin privileges to read arbitrary files on Ivanti Connect Secure and Policy Secure appl...

Feb 11, 2025
CVE-2026-27008
6.7

OpenClaw versions before 2026.2.15 contain a path traversal vulnerability in the skill installation process. The bug allows malicious skill packages t...

Feb 20, 2026
CVE-2025-20614
6.7

This vulnerability in Intel CIP software allows local attackers to escalate privileges by controlling file paths. It affects systems running vulnerabl...

Nov 11, 2025
CVE-2025-26684
6.7

This vulnerability in Microsoft Defender for Endpoint allows an authorized attacker to manipulate file paths to achieve local privilege escalation. It...

May 13, 2025
CVE-2024-38049
6.6

CVE-2024-38049 is a remote code execution vulnerability in Windows Distributed Transaction Coordinator (MSDTC) that allows an authenticated attacker t...

Jul 9, 2024
CVE-2025-69621
6.5

An arbitrary file overwrite vulnerability in Comic Book Reader v1.0.95 allows attackers to overwrite critical internal files during file import. This ...

Feb 4, 2026
CVE-2026-20925
6.5

This vulnerability allows an attacker to manipulate file paths in Windows NTLM authentication, enabling network spoofing attacks. Attackers can potent...

Jan 13, 2026
CVE-2026-20872
6.5

This vulnerability allows an attacker to manipulate file paths in Windows NTLM authentication, enabling network spoofing attacks. Attackers could impe...

Jan 13, 2026
CVE-2025-14059
6.5

The EmailKit WordPress plugin up to version 1.6.1 contains a path traversal vulnerability that allows authenticated attackers with Author permissions ...

Jan 7, 2026
CVE-2021-4472
6.5

The mistral-dashboard plugin for OpenStack contains a local file inclusion vulnerability in the 'Create Workbook' feature. This allows authenticated u...

Nov 26, 2025
CVE-2025-13380
6.5

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to read arbitrary files on the server through the AI E...

Nov 25, 2025
CVE-2025-8050
6.5

This path traversal vulnerability in OpenText Flipper allows attackers to access arbitrary files on the server by manipulating file paths. It affects ...

Oct 21, 2025
CVE-2025-8048
6.5

This path traversal vulnerability in OpenText Flipper allows attackers to access arbitrary files on the server by manipulating file path parameters. I...

Oct 20, 2025
CVE-2025-59185
6.5

This vulnerability in Windows Core Shell allows attackers to manipulate file paths or names remotely, enabling spoofing attacks over networks. It affe...

Oct 14, 2025
CVE-2025-24996
6.5

This vulnerability in Windows NTLM allows attackers to manipulate file paths or names during network authentication, enabling spoofing attacks. It aff...

Mar 11, 2025
CVE-2025-24054
KEV EPSS 11.2% 6.5

This vulnerability in Windows NTLM allows an attacker to manipulate file paths or names externally, enabling network spoofing attacks. It affects Wind...

Mar 11, 2025
CVE-2025-25478
6.5

This vulnerability in Syspass 3.2.x allows attackers to access the web application's source code by exploiting improper filename handling in the accou...

Feb 28, 2025
CVE-2024-47265
6.5

This CVE describes a path traversal vulnerability in Synology Active Backup for Business that allows remote authenticated users to write specific file...

Feb 13, 2025
CVE-2025-0111
KEV 6.5

An authenticated file read vulnerability in Palo Alto Networks PAN-OS software allows authenticated attackers with management web interface access to ...

Feb 12, 2025
CVE-2025-21377
6.5

This vulnerability allows attackers to spoof NTLM hash disclosure, potentially enabling credential theft and lateral movement. It affects systems usin...

Feb 11, 2025
CVE-2025-0630
6.5

This vulnerability allows any authenticated user on affected Western Telematic (WTI) products to perform local file inclusion attacks, potentially acc...

Feb 4, 2025
CVE-2024-33860
6.5

This Local File Inclusion vulnerability in Logpoint versions before 7.4.0 allows attackers to read arbitrary files on the system through the File Syst...

May 7, 2024
CVE-2025-12915
6.4

This vulnerability in 70mai X200 dashcams allows local attackers to hijack init scripts through file inclusion, potentially enabling persistent unauth...

Nov 8, 2025
CVE-2025-2982
6.3

This critical vulnerability in Legrand SMS PowerView 1.x allows remote attackers to perform file inclusion attacks by manipulating the redirect argume...

Mar 31, 2025
CVE-2024-9275
6.3

This critical vulnerability in 123solar allows remote attackers to perform file inclusion attacks via the PROTOCOLx parameter in /admin/admin_invt2.ph...

Sep 27, 2024
CVE-2024-7911
6.3

This vulnerability allows remote attackers to perform file inclusion attacks on SourceCodester Simple Online Bidding System 1.0 by manipulating the 'p...

Aug 18, 2024
CVE-2024-7496
6.3

This vulnerability allows remote attackers to perform file inclusion attacks by manipulating the 'page' parameter in /index.php of itsourcecode Airlin...

Aug 6, 2024
CVE-2024-23317
6.3

This vulnerability allows an attacker with local access to Gallagher Controller 6000/7000 systems to control file paths and execute arbitrary code. It...

Jul 11, 2024
CVE-2024-25965
6.1

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contain a path traversal vulnerability where an attacker with local high privileges can control f...

May 14, 2024
CVE-2025-0202
5.5

A potential file inclusion vulnerability exists in TCS BaNCS 10 through the /REPORTS/REPORTS_SHOW_FILE.jsp endpoint. Attackers could manipulate the Fi...

Jan 4, 2025
CVE-2025-48067
5.4

OctoPrint versions up to 1.11.1 contain a file exfiltration vulnerability where authenticated users with FILE_UPLOAD permission can move readable host...

Jun 10, 2025
CVE-2025-11738
5.3

The Media Library Assistant WordPress plugin has a vulnerability that allows unauthenticated attackers to read arbitrary AI, EPS, PDF, and PS files on...

Oct 18, 2025
CVE-2024-22341
5.3

This vulnerability in IBM Watson Query on Cloud Pak for Data allows unauthorized access to remote data sources due to improper privilege management. A...

Feb 22, 2025
CVE-2025-67461
5.0

This vulnerability in Zoom Rooms for macOS allows authenticated local users to control file paths, potentially leading to information disclosure. It a...

Dec 10, 2025
CVE-2025-64738
5.0

This vulnerability in Zoom Workplace for macOS allows an authenticated user with local access to control file names or paths, potentially leading to i...

Nov 13, 2025
CVE-2025-11973
4.9

The įŽ€æ•°é‡‡é›†å™¨ WordPress plugin has an arbitrary file read vulnerability in versions up to 2.6.3. Authenticated attackers with Administrator or h...

Nov 21, 2025
CVE-2024-38657
4.9

This vulnerability allows remote authenticated attackers with admin privileges to write arbitrary files by controlling file names in Ivanti Connect Se...

Feb 21, 2025
CVE-2024-12875
4.9

This vulnerability allows authenticated WordPress administrators to perform directory traversal attacks through the file download functionality, enabl...

Dec 21, 2024
CVE-2025-27137
4.4

This vulnerability allows authenticated users with SYSTEM_CONFIGURATION permission in Dependency-Track to craft malicious notification templates that ...

Feb 24, 2025
CVE-2025-65799
4.3

CVE-2025-65799 is a path traversal vulnerability in usememos memos v0.25.2 that allows attackers to access files outside the intended directory throug...

Dec 8, 2025
CVE-2025-64739
4.3

This vulnerability in Zoom Clients allows unauthenticated attackers to control file paths, potentially leading to information disclosure via network a...

Nov 13, 2025
CVE-2024-12357
4.3

This vulnerability allows remote attackers to perform file inclusion attacks via the 'page' parameter in /index.php in SourceCodester Best House Renta...

Dec 9, 2024
CVE-2026-21249
3.3

This vulnerability allows an unauthorized local attacker to manipulate file paths in Windows NTLM authentication, potentially enabling spoofing attack...

Feb 10, 2026
CVE-2025-8998
3.1

This vulnerability allows authenticated users with operator or administrator privileges to upload specially named files to a temporary directory, caus...

Nov 11, 2025
CVE-2025-12654
2.7

The WPvivid Backup & Migration WordPress plugin allows authenticated attackers with Administrator privileges to create arbitrary directories on the se...

Dec 21, 2025
CVE-2026-23835
N/A

This vulnerability in LobeHub allows attackers to bypass file upload validation and quota limits by intercepting and modifying upload requests. Attack...

Jan 30, 2026
CVE-2025-66003
N/A

An External Control of File Name or Path vulnerability in smb4k's mounthelper allows local users to escalate privileges to root by controlling the con...

Jan 8, 2026
CVE-2025-64486
N/A

This vulnerability in calibre e-book manager allows attackers to write arbitrary files to the filesystem when processing malicious FB2 (FictionBook) f...

Nov 8, 2025

About CWE-73 (CWE-73)

Our database tracks 148 CVEs classified as CWE-73, with 26 rated critical and 72 rated high severity. The average CVSS score for CWE-73 vulnerabilities is 7.5.

External reference: View CWE-73 on MITRE CWE →

Monitor CWE-73 Vulnerabilities

Get alerted when new CWE-73 CVEs affect your infrastructure.

Start Monitoring Free