Skip to main content

CWE archive

CWE-73 CVEs

Programmatic archive

512 CVEs tagged with CWE-7372 Critical, 235 High, 183 Medium, 22 Low, 0 Unrated.

CVE-2026-27008

Published Feb 20, 2026

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the pe…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-26202

Published Feb 19, 2026

Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a loca…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-26361

Published Feb 19, 2026

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exp…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26360

Published Feb 19, 2026

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exp…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26359

Published Feb 19, 2026

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exp…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24708

Published Feb 18, 2026

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering…

CVSS 8.2 · High
evidence mentions
7
Buzz score
36.8

CVE-2026-25964

Published Feb 13, 2026

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-61879

Published Feb 12, 2026

In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-1669

Published Feb 11, 2026

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local file…

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-26158

Published Feb 11, 2026

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unva…

CVSS 7.0 · High
evidence mentions
7
Buzz score
40.8

CVE-2026-26157

Published Feb 11, 2026

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specifi…

CVSS 7.0 · High
evidence mentions
7
Buzz score
40.8

CVE-2025-54162

Published Feb 11, 2026

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-25636

Published Feb 6, 2026

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files wr…

CVSS 8.2 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-25628

Published Feb 6, 2026

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-co…

CVSS 8.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-64712

Published Feb 4, 2026

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-37080

Published Feb 3, 2026

webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers c…

CVSS 7.2 · High

CVE-2020-37078

Published Feb 3, 2026

i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete…

CVSS 7.2 · High

CVE-2024-5986

Published Feb 2, 2026

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint t…

CVSS 9.1 · Critical

CVE-2026-23835

Published Jan 30, 2026

LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the up…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2021-47871

Published Jan 21, 2026

Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoin…

CVSS 8.6 · High

CVE-2021-47746

Published Jan 21, 2026

NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API…

CVSS 8.6 · High

CVE-2025-53912

Published Jan 20, 2026

An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2026-23529

Published Jan 16, 2026

Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery…

CVSS 7.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2025-66292

Published Jan 15, 2026

DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Aut…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 176-200 of 512 CVEsPage 8 of 21