VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-64838High· 8.3PoC
2w ago

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequenc…

▾ MidnightICEcoder · icecoder/icecoderEPSS 0.52%via NVD
CVE-2026-64836High· 8.8
2w ago

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, whi…

▾ TwilightICEcoder · icecoder/icecoderEPSS 0.61%via NVD
CVE-2026-9166High· 7.5
2w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.…

▾ TwilightGIS Informatics · GisLab Laboratory Management SystemEPSS 0.50%via NVD
CVE-2026-15019High· 7.5
2w ago

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read t…

▾ Twilightkamalyon · Direct Download for WooCommerceEPSS 0.68%via NVD
CVE-2026-49836Medium· 4.6PoC
2w ago

psd-tools: arbitrary file write via smart-object filename

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …

▾ Twilightpsd-tools · psd-toolsEPSS 0.19%via CVEORG
CVE-2026-86775High· 8.6
2w ago

knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API

knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/t…

▾ Twilightknowns-dev · knownsEPSS 0.75%via NVD
CVE-2026-78485High· 7.3
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated a…

▾ Twilightdell · secure_connect_gatewayEPSS 0.37%via NVD
CVE-2026-59179High· 8.3
2w ago

@openhop/server: Path Traversal in Flow ID File Operations

@openhop/server: Path Traversal in Flow ID File Operations

▾ Twilightopenhop · @openhop/servervia GHSA
CVE-2026-88069Critical· 9.3
2w ago

Pandora contains a path traversal vulnerability in its archive extraction worker

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination rem…

▾ Midnightpandora-analysis · pandoraEPSS 0.50%via NVD
CVE-2025-58363Medium· 5.5
2w ago

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2026-86099High· 8.2
2w ago

Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences

Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences. Attackers can craft malicious …

▾ TwilightChainlit · chainlitEPSS 0.60%via NVD
CVE-2026-87817High· 8.8
2w ago

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…

▾ Twilightgitpython_project · gitpythonEPSS 0.40%via NVD
CVE-2026-19729Medium· 4.9
2w ago

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm admini…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.48%via NVD
CVE-2026-87030High· 8.5
2w ago

Tanium addressed a path traversal vulnerability in Comply.

Tanium addressed a path traversal vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.44%via NVD
CVE-2026-14505Medium· 6.6
2w ago

Tanium addressed a path traversal vulnerability in Tanium Data Service.

Tanium addressed a path traversal vulnerability in Tanium Data Service.

▾ SunlitTanium · Tanium Data ServiceEPSS 0.31%via NVD
CVE-2026-87023High· 8.5
2w ago

Tanium addressed a path traversal vulnerability in Comply.

Tanium addressed a path traversal vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.46%via NVD
CVE-2026-53956Medium· 5.4
2w ago

Rattler vulnerable to package cache path traversal via conda package build string

Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling packag…

▾ Sunlitconda · rattler_cacheEPSS 0.33%via CVEORG
GHSA-qjrq-cvv4-3g9wHigh· 8.8
2w ago

Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools

Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools

▾ Twilightknowns · knownsvia GHSA
CVE-2026-53581Critical· 9.0PoC
2w ago

OPNsense is a FreeBSD based firewall and routing platform

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite a…

▾ Abyssalopnsense · coreEPSS 0.47%via NVD
CVE-2026-86995Medium· 4.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration with…

▾ Sunlitn8n · n8nEPSS 0.40%via NVD
CVE-2026-86079Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An i…

▾ Sunlitn8n · n8nEPSS 0.49%via NVD
GHSA-2q42-4q24-7rgvHigh· 7.1
2w ago

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

▾ Twilighttypespec · @typespec/openapi3via GHSA
CVE-2026-78624Medium· 4.9
2w ago

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

▾ Sunlitokta · access_gatewayEPSS 0.46%via NVD
CVE-2026-77110High· 7.6
2w ago

Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass

Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerabil…

▾ Twilightadobe · commerceEPSS 1.1%via NVD
CVE-2026-81377Medium· 6.5
2w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

▾ Sunlitmicrosoft · visual_studio_codeEPSS 0.76%via NVD
CVE-2026-79904Medium· 5.0
2w ago

Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass

Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability t…

▾ Sunlitadobe · photoshop_mobileEPSS 0.19%via NVD
CVE-2026-78461High· 7.4
2w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · visual_studio_codeEPSS 1.0%via NVD
CVE-2026-69807High· 8.0
2w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.87%via NVD
CVE-2026-69445High· 7.8
2w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally.

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.37%via NVD
CVE-2026-62801Medium· 6.5
2w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.76%via NVD
CWE-22 vulnerabilities (CVEs) — page 10 · VulnSea