VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

891 CVEsRSS

CVE-2026-62369High· 8.1
today

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/comm…

Twilightkubeedge · kubeedgevia CVEORG
CVE-2026-63416Low· 3.7
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL …

Sunlitjgraph · drawiovia NVD
CVE-2026-53940High· 8.8
today

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…

Twilightconda · condavia NVD
CVE-2026-15801High· 8.0⚖ disputed
today

A vulnerability was found in CRI-O related to the container checkpoint and restore feature

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with suffic…

TwilightRed Hat · cri-oEPSS 0.31%via NVD
CVE-2026-94185Medium· 5.5
today

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no containment check, so a name containi…

Sunlitnvm-sh · nvmEPSS 0.29%via NVD
CVE-2026-94049Medium· 4.3PoC
yesterday

A flaw has been found in 06ketan slideshot up to 4.4.0

A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of the argument htmlPath causes path traversal. The attack is possible to be carr…

Twilight06ketan · slideshotEPSS 0.32%via NVD
CVE-2026-94046Medium· 4.3PoC
yesterday

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8

A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manipulation of the argument projectRootPat…

Twilight0215AndrewFeng · ACE-MCPEPSS 0.45%via NVD
CVE-2026-94044High· 7.3
yesterday

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content lead…

Twilight03-lovepreetSingh · MCPEPSS 0.42%via NVD
CVE-2026-94037Medium· 4.3
yesterday

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405

A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affects the function ControlFlowNode of the file main.py of the component analyze_csv_data MCP tool. This manipulation of…

Sunlit00Kisumi00 · mcp-file-analyzerEPSS 0.33%via NVD
CVE-2026-93988Medium· 6.5PoC
2d ago

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email par…

Twilightwebkul · qloappsEPSS 0.37%via NVD
CVE-2026-93992High· 8.1
2d ago

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing dir…

TwilightGopeedLab · gopeedEPSS 0.80%via NVD
CVE-2026-93986Low· 3.1
2d ago

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent…

Sunlitrclone · rcloneEPSS 0.20%via NVD
CVE-2026-85272Medium· 4.3PoC
3d ago

Open edX Platform enables the authoring and delivery of online learning at any scale

Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate safe_extractall targets by comparing resolved…

Twilightopenedx · openedx-platformEPSS 0.33%via NVD
CVE-2026-84086High· 7.2
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

TwilightIBM · Guardium Data ProtectionEPSS 0.65%via NVD
CVE-2017-20284High· 7.5PoC
3d ago

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

MidnightCaucho Technology, Inc. · ResinEPSS 0.96%via NVD
CVE-2026-82896High· 7.6
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

TwilightIBM · Guardium Data ProtectionEPSS 0.36%via NVD
CVE-2026-62278High· 8.1
3d ago

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name passed from Controlle…

Twilighthargata · lubelogEPSS 0.34%via NVD
CVE-2026-63445High· 7.1
3d ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…

Twilightperses · github.com/perses/persesEPSS 0.56%via NVD
CVE-2025-14753High· 7.5
3d ago

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

TwilightIBM · Cloud Pak for DataEPSS 0.62%via NVD
CVE-2026-21822Medium· 6.3
3d ago

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially…

SunlitHCL Software · HCL AppScan 360°EPSS 0.21%via NVD
CVE-2026-40535Medium· 6.5
3d ago

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write …

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write …

SunlitSynology · DiskStation Manager (DSM)EPSS 0.43%via NVD
CVE-2026-40536Medium· 4.3
3d ago

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users t…

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users t…

SunlitSynology · DiskStation Manager (DSM)EPSS 0.37%via NVD
CVE-2026-16777Medium· 4.9
3d ago

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes i…

Sunlitjkohlbach · Store Exporter – Export WooCommerce Products, Orders, Subscriptions, CustomersEPSS 0.66%via NVD
CVE-2026-14323High· 7.5
3d ago

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated att…

Twilightprintcart · Printcart Store – Web to Print Product Designer for WooCommerceEPSS 0.94%via NVD
CVE-2026-70200Critical· 10.0
4d ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure Logic AppsEPSS 0.58%via NVD
CVE-2026-70009Critical· 9.3
4d ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure ARCEPSS 0.47%via NVD
CVE-2026-54670Critical· 9.1
4d ago

WeGIA is a web manager for charitable institutions

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controlle…

MidnightLabRedesCefetRJ · WeGIAEPSS 0.55%via NVD
CVE-2026-54613Medium· 5.4
4d ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php returns the attacker-controlled theme parameter without s…

Sunlitgivanz · VvvebEPSS 0.24%via NVD
CVE-2026-54612High· 8.8
4d ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file …

Twilightgivanz · VvvebEPSS 0.49%via NVD
CVE-2026-54520High· 8.1PoC
4d ago

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.…

MidnightvmDeshpande · ai-agent-automationEPSS 0.40%via NVD
CWE-22 vulnerabilities (CVEs) · VulnSea