Skip to main content

CWE archive

CWE-73 CVEs

Programmatic archive

512 CVEs tagged with CWE-7372 Critical, 235 High, 183 Medium, 22 Low, 0 Unrated.

CVE-2024-7497

Published Aug 6, 2024

A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The m…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7496

Published Aug 6, 2024

A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The manip…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6937

Published Jul 21, 2024

A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.ph…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6467

Published Jul 17, 2024

The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in all ver…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-39904

Published Jul 11, 2024

VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system.…

CVSS 8.8 · High

CVE-2024-23317

Published Jul 11, 2024

External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to perform arbitrary code executio…

CVSS 6.3 · Medium

CVE-2024-37149

Published Jul 10, 2024

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39303

Published Jul 1, 2024

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorize…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5334

Published Jun 27, 2024

A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' param…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27175

Published Jun 14, 2024

Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can read any file on the printer. As for the affected products/m…

CVSS 4.4 · Medium

CVE-2024-37295

Published Jun 11, 2024

Aimeos is an Open Source e-commerce framework for online shops. Starting in version 2024.01.1 and prior to version 2024.04.5, a user with administrative privileges can upload file…

CVSS 7.2 · High

CVE-2024-36473

Published Jun 10, 2024

Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local Denial of Service (DoS) and under s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25975

Published May 29, 2024

The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are not filtered properly and therefore an arbitrary file can…

CVSS 6.5 · Medium

CVE-2024-28826

Published May 29, 2024

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient pe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20366

Published May 15, 2024

A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, loc…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27945

Published May 14, 2024

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the roo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27944

Published May 14, 2024

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload firmware files to the root installation dir…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27943

Published May 14, 2024

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow a privileged user to upload generic files to the root installation dire…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25965

Published May 14, 2024

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit thi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4818

Published May 14, 2024

A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. The m…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0087

Published May 14, 2024

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the fil…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 376-400 of 512 CVEsPage 16 of 21