Skip to main content

CWE archive

CWE-73 CVEs

Programmatic archive

512 CVEs tagged with CWE-7372 Critical, 235 High, 183 Medium, 22 Low, 0 Unrated.

CVE-2026-22783

Published Jan 12, 2026

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-66003

Published Jan 8, 2026

An External Control of File Name or Path vulnerability in smb4k allowsl ocal users to perform a local root exploit via smb4k mounthelper if they can access and control the content…

CVSS 7.3 · High

CVE-2025-14059

Published Jan 7, 2026

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in th…

CVSS 6.5 · Medium

CVE-2025-68428

Published Jan 5, 2026

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusi…

CVSS 9.2 · Critical
evidence mentions
11
Buzz score
44.4
Vendor/product tagsBeta · best-effort

CVE-2025-62842

Published Jan 2, 2026

An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the v…

CVSS 7.0 · High
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-12654

Published Dec 21, 2025

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This…

CVSS 2.7 · Low

CVE-2025-68478

Published Dec 19, 2025

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the serve…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68155

Published Dec 16, 2025

@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unaut…

CVSS 7.5 · High

CVE-2025-66449

Published Dec 16, 2025

ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwritin…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13320

Published Dec 12, 2025

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supp…

CVSS 6.8 · Medium

CVE-2025-65473

Published Dec 11, 2025

An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary cod…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-67461

Published Dec 10, 2025

External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65799

Published Dec 8, 2025

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36878

Published Dec 5, 2025

ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verifi…

CVSS 8.7 · High

CVE-2025-12529

Published Dec 2, 2025

The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versi…

CVSS 8.8 · High

CVE-2021-4472

Published Nov 26, 2025

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files co…

CVSS 6.5 · Medium

CVE-2025-13380

Published Nov 25, 2025

The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1. This is due to i…

CVSS 6.5 · Medium

CVE-2025-30201

Published Nov 21, 2025

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attacker…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11973

Published Nov 21, 2025

The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the __kds_flag functionality that imports featured images. This…

CVSS 4.9 · Medium
Showing 201-225 of 512 CVEsPage 9 of 21