Vulnerabilities (CVE)

Filtered by CWE-73
Total 445 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-0100 2 Linux, Nvidia 2 Linux Kernel, Triton Inference Server 2026-06-17 N/A 6.5 MEDIUM
NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CVE-2024-0087 2 Linux, Nvidia 2 Linux Kernel, Triton Inference Server 2026-06-17 N/A 9.0 CRITICAL
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2023-5816 1 Bowo 1 Code Explorer 2026-06-17 N/A 4.9 MEDIUM
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress related files. This makes it possible for authenticated attackers, with administrator-level access, to read files outside of the WordPress instance.
CVE-2023-4634 1 Davidlingren 1 Media Library Assistant 2026-06-17 N/A 9.8 CRITICAL
The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.
CVE-2023-4191 1 Resort Reservation System Project 1 Resort Reservation System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-236234 is the identifier assigned to this vulnerability.
CVE-2023-47147 1 Ibm 1 Sterling Secure Proxy 2026-06-17 N/A 5.9 MEDIUM
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.
CVE-2023-45588 1 Fortinet 1 Forticlient 2026-06-17 N/A 8.2 HIGH
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.
CVE-2023-36764 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 8.8 HIGH
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-36019 1 Microsoft 2 Azure Logic Apps, Power Platform 2026-06-17 N/A 9.6 CRITICAL
Microsoft Power Platform Connector Spoofing Vulnerability
CVE-2023-35384 1 Microsoft 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more 2026-06-17 N/A 5.4 MEDIUM
Windows HTML Platforms Security Feature Bypass Vulnerability
CVE-2023-35308 1 Microsoft 11 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 8 more 2026-06-17 N/A 6.5 MEDIUM
Windows MSHTML Platform Security Feature Bypass Vulnerability
CVE-2023-2554 1 Bumsys Project 1 Bumsys 2026-06-17 N/A 7.2 HIGH
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
CVE-2023-29324 1 Microsoft 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more 2026-06-17 N/A 6.5 MEDIUM
Windows MSHTML Platform Security Feature Bypass Vulnerability
CVE-2023-28603 2 Microsoft, Zoom 2 Windows, Virtual Desktop Infrastructure 2026-06-17 N/A 7.7 HIGH
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
CVE-2023-26282 1 Ibm 1 Watson Cp4d Data Stores 2026-06-17 N/A 4.2 MEDIUM
IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the system to modify files or data on the system. IBM X-Force ID: 248415.
CVE-2023-21800 1 Microsoft 1 Windows Server 2008 2026-06-17 N/A 7.8 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVE-2023-21566 1 Microsoft 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 2026-06-17 N/A 7.8 HIGH
Visual Studio Elevation of Privilege Vulnerability
CVE-2023-1105 1 Flatpress 1 Flatpress 2026-06-17 N/A 8.1 HIGH
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2023-1070 1 Teampass 1 Teampass 2026-06-17 N/A 7.1 HIGH
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
CVE-2022-4983 2026-06-17 N/A N/A
TEC-IT TBarCode version 11.15 contains a vulnerability in the TBarCode11.ocx ActiveX/OCX control's licensing handling (INI-file based) that can be abused to cause remote creation of files on the host filesystem. Depending on where files can be created and which filenames are allowed, this can allow attackers to write files that lead to code execution or persistence under the context of the hosting process.