CVEs classified under CWE-73, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-101148 — CVSS 10.0 (critical): The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or…
CVE-2026-20358 — CVSS 10.0 (critical): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a…
CVE-2026-50148 — CVSS 10.0 (critical): Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19…
CVE-2025-71338 — CVSS 10.0 (critical): Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write…
CVE-2026-39907 — CVSS 10.0 (critical): Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that…
CVE-2026-27211 — CVSS 10.0 (critical): Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file…
CVE-2026-16338 — CVSS 9.9 (critical): IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write…
CVE-2026-63343 — CVSS 9.9 (critical): Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink…
CVE-2026-48753 — CVSS 9.9 (critical): Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path…
CVE-2026-48752 — CVSS 9.9 (critical): Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used…
CVE-2026-48750 — CVSS 9.9 (critical): Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the…
CVE-2026-48749 — CVSS 9.9 (critical): Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or…
CVE-2026-72842 — CVSS 9.9 (critical): luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container…
CVE-2026-72841 — CVSS 9.9 (critical): luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path…
CVE-2026-14480 — CVSS 9.9 (critical): OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The…
CVE-2026-90817 — CVSS 9.8 (critical): An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in…
CVE-2026-88899 — CVSS 9.8 (critical): knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote…
CVE-2026-66302 — CVSS 9.8 (critical): External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
CVE-2026-86189 — CVSS 9.8 (critical): WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to…
CVE-2026-59683 — CVSS 9.8 (critical): The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682)…
CVE-2026-56705 — CVSS 9.8 (critical): Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject…
CVE-2026-17184 — CVSS 9.8 (critical): IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
CVE-2026-17482 — CVSS 9.8 (critical): IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
CVE-2025-71334 — CVSS 9.8 (critical): Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that…
CVE-2025-71333 — CVSS 9.8 (critical): Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType…
CVE-2026-39006 — CVSS 9.8 (critical): An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
CVE-2026-11526 — CVSS 9.8 (critical): GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in…
CVE-2026-30281 — CVSS 9.8 (critical): An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import…
CVE-2026-30276 — CVSS 9.8 (critical): An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via…
CVE-2020-37080 — CVSS 9.8 (critical): webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated…
CVE-2025-6237 — CVSS 9.8 (critical): A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET…
CVE-2025-54945 — CVSS 9.8 (critical): An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers…
CVE-2025-43951 — CVSS 9.8 (critical): LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via…
CVE-2025-29709 — CVSS 9.8 (critical): SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.
CVE-2025-29708 — CVSS 9.8 (critical): SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.
CVE-2024-55372 — CVSS 9.8 (critical): Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by…
CVE-2024-55371 — CVSS 9.8 (critical): Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by…
CVE-2024-11838 — CVSS 9.8 (critical): External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocumented API…
CVE-2024-9142 — CVSS 9.8 (critical): External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems…
CVE-2024-8517 — CVSS 9.8 (critical): SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute…
CVE-2023-47862 — CVSS 9.8 (critical): A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A…
CVE-2023-4634 — CVSS 9.8 (critical): The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and…
CVE-2021-38477 — CVSS 9.8 (critical): There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the…
CVE-2026-77006 — CVSS 9.6 (critical): The WebTotem Backups WordPress plugin before 1.1.0 does not validate a user-supplied file path, does not check the capability of the user…
CVE-2026-77005 — CVSS 9.6 (critical): The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not…
CVE-2026-77016 — CVSS 9.6 (critical): The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not…
CVE-2026-8043 — CVSS 9.6 (critical): External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files…
CVE-2025-53912 — CVSS 9.6 (critical): An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted…
CVE-2026-85520: Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint…