Skip to main content

CWE archive

CWE-73 CVEs

Programmatic archive

549 CVEs tagged with CWE-7380 Critical, 255 High, 191 Medium, 23 Low, 0 Unrated.

CVE-2026-25636

Published Feb 6, 2026

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files wr…

CVSS 8.2 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-25628

Published Feb 6, 2026

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-co…

CVSS 8.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-64712

Published Feb 4, 2026

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2020-37080

Published Feb 3, 2026

webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers c…

CVSS 7.2 · High

CVE-2020-37078

Published Feb 3, 2026

i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete…

CVSS 7.2 · High

CVE-2024-5986

Published Feb 2, 2026

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint t…

CVSS 9.1 · Critical

CVE-2026-23835

Published Jan 30, 2026

LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the up…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2021-47871

Published Jan 21, 2026

Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoin…

CVSS 8.6 · High

CVE-2021-47746

Published Jan 21, 2026

NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API…

CVSS 8.6 · High

CVE-2025-53912

Published Jan 20, 2026

An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-23529

Published Jan 16, 2026

Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery…

CVSS 7.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2025-66292

Published Jan 15, 2026

DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Aut…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-22783

Published Jan 12, 2026

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-66003

Published Jan 8, 2026

An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the content…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-14059

Published Jan 7, 2026

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in th…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2025-68428

Published Jan 5, 2026

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusi…

CVSS 9.2 · Critical
evidence mentions
11
Buzz score
44.4
Vendor/product tagsBeta · best-effort

CVE-2025-62842

Published Jan 2, 2026

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the v…

CVSS 7.0 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-12654

Published Dec 21, 2025

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This…

CVSS 2.7 · Low
evidence mentions
6
Buzz score
31.0

CVE-2025-68478

Published Dec 19, 2025

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the serve…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68155

Published Dec 16, 2025

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unaut…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1

CVE-2025-66449

Published Dec 16, 2025

ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwritin…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-13320

Published Dec 12, 2025

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supp…

CVSS 6.8 · Medium
evidence mentions
8
Buzz score
28.5
Showing 226-250 of 549 CVEsPage 10 of 22