CWE-73
CVEs classified under CWE-73, newest first.
200 CVEsRSS
CVE-2026-65939Medium· 6.8In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
CVE-2026-72742High· 8.6DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the u…
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the u…
CVE-2026-19353Medium· 5.0A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can …
CVE-2026-76217Medium· 6.5GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GHSA-hh9p-6wh2-4mfcMedium· 6.5GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GHSA-hmq2-w58f-27jcHigh· 8.2GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
CVE-2026-66310High· 7.7External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2026-18806High· 7.1External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.
GHSA-88pr-878c-24wfHighFlowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
CVE-2026-65802High· 7.4Microsoft Edge for Android Information Disclosure Vulnerability
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
GHSA-3f7w-8rr8-f37fHigh· 8.1GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GHSA-539m-9xh6-q6rrMedium· 6.5GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
CVE-2026-64816Medium· 6.5RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking…
CVE-2026-67429Critical· 10.0Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
GHSA-68r5-9hpg-7qw9Critical· 9.4OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
CVE-2026-55628Medium· 6.1ImageMagick: Policy Bypass in concatenate operation due to missing checks
ImageMagick: Policy Bypass in concatenate operation due to missing checks
CVE-2026-65896High· 7.1Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), …
GHSA-xmc9-4f2h-jf9cHighn8n: Edit Image Node Format Injection Allows Arbitrary File Write
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
CVE-2026-58420MediumGitea: Local File Inclusion via file:// URI in Migration Restore
Gitea: Local File Inclusion via file:// URI in Migration Restore
CVE-2026-46336High· 7.1Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated users can rename uploaded files with path traversal sequences b…
CVE-2026-55002High· 8.8Microsoft SQL Server Elevation of Privilege Vulnerability
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-54108Medium· 6.5Microsoft SharePoint Server Spoofing Vulnerability
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-50462High· 7.8Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-61462High· 8.6PoCmcp-gitlab Path Traversal via job_id Parameter
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to e…
CVE-2026-13014NoneA vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, c…
A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, c…
CVE-2026-15540Medium· 4.3A vulnerability was detected in SourceCodester Online Book Store System 1.0
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument pa…
CVE-2026-53449Medium· 6.0Coturn is a free open source implementation of TURN and STUN Server
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated a…
CVE-2026-14480Critical· 9.9OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database fi…
GHSA-wm45-qh3g-v83fHigh· 7.7mcp-atlassian: Arbitrary server-side file read via attachment upload
mcp-atlassian: Arbitrary server-side file read via attachment upload
GHSA-52vm-mxx8-f227High· 7.7Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths