VulnSea

CWE-73

CVEs classified under CWE-73, newest first.

200 CVEsRSS

CVE-2026-35076High· 8.1
3mo ago

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.53%via NVD
CVE-2026-8450Critical· 9.1
4mo ago

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open()

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subpro…

▾ MidnightEPSS 2.6%via NVD
CVE-2026-30282Critical· 9.0
6mo ago

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

▾ Midnightuxgroupllc · cast_to_tvEPSS 0.57%via NVD
CVE-2026-30284High· 8.6
6mo ago

An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

▾ Twilightuxgroupllc · voice_recorderEPSS 0.21%via NVD
CVE-2026-30281Critical· 9.8
6mo ago

An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

▾ Midnightmaru · neo.maruEPSS 0.86%via NVD
CVE-2026-30276Critical· 9.8
6mo ago

An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

▾ Midnightdeftpdf · document_translatorEPSS 0.83%via NVD
CVE-2026-0965Low· 3.3
6mo ago

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability c…

▾ Sunlitlibssh · libsshEPSS 0.16%via NVD
CVE-2026-24708High· 8.2
7mo ago

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend t…

▾ TwilightOpenStack · NovaEPSS 0.38%via NVD
CVE-2026-1669High· 7.5
7mo ago

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

▾ Twilightkeras · kerasEPSS 0.31%via NVD
CVE-2026-26158High· 7.0
7mo ago

A flaw was found in BusyBox

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-26157High· 7.0PoC
7mo ago

A flaw was found in BusyBox

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended dire…

▾ MidnightEPSS 0.60%via NVD
CVE-2026-20925Medium· 6.5
8mo ago

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 18%via NVD
CVE-2026-20872Medium· 6.5
8mo ago

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 20%via NVD
CVE-2025-68428High· 7.5PoC
8mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsani…

▾ Midnightparall · jspdfEPSS 2.2%via NVD
CVE-2025-62842High· 7.8
8mo ago

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We h…

▾ Twilightqnap · hybrid_backup_syncEPSS 0.26%via NVD
CVE-2025-67461Medium· 5.0
9mo ago

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.

▾ Sunlitzoom · roomsEPSS 0.14%via NVD
CVE-2025-65799Medium· 4.3
9mo ago

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

▾ Sunlitusememos · memosEPSS 0.21%via NVD
CVE-2025-10058High· 8.1
1y ago

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. …

▾ TwilightEPSS 0.62%via NVD
CVE-2024-13984None
1y ago

QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server

QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rp…

▾ SunlitEPSS 0.82%via NVD
CVE-2024-10492Low· 2.7
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order t…

▾ SunlitRed Hat · keycloakEPSS 0.71%via NVD
CWE-73 vulnerabilities (CVEs) — page 7 · VulnSea