VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-74239High· 7.2PoC
2w ago

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended ex…

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended ex…

▾ Midnightxenforo · xenforoEPSS 0.89%via NVD
CVE-2026-77104High· 7.5
2w ago

CommServe contained a path traversal issue affecting information disclosure

CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

▾ Twilightcommvault · commvaultEPSS 0.56%via NVD
CVE-2026-77091High· 7.8
2w ago

DataCube contained a path traversal issue affecting security feature enforcement

DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.

▾ Twilightcommvault · commvaultEPSS 0.18%via NVD
CVE-2026-74859Medium· 6.8
2w ago

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or…

▾ SunlitRed Hat · gnome-tweaksEPSS 0.17%via NVD
CVE-2026-78677High· 7.5
2w ago

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside …

GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

▾ Twilightgitpython · gitpythonEPSS 0.65%via OSV
CVE-2026-79676High
2w ago

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

▾ Twilightnltk · nltkEPSS 0.45%via OSV
CVE-2026-86542Critical· 9.1
2w ago

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the impor…

▾ Midnightknowns-dev · knownsEPSS 0.74%via NVD
CVE-2026-86541High· 8.3
2w ago

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths c…

▾ Twilightknowns-dev · knownsEPSS 0.77%via NVD
CVE-2026-86538High· 7.5
2w ago

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the tem…

▾ Twilightknowns-dev · knownsEPSS 0.98%via NVD
CVE-2026-86439High· 8.8
2w ago

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory…

▾ Twilightknowns-dev · knownsEPSS 1.1%via NVD
CVE-2026-80131High· 7.4
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated a…

▾ Twilightdell · secure_connect_gatewayEPSS 0.78%via NVD
CVE-2026-80129Medium· 6.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated a…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.68%via NVD
CVE-2026-6377High· 7.5
2w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Man…

▾ TwilightNext4Biz Information Technologies Inc. · CSM (Customer Service Management)EPSS 0.50%via NVD
CVE-2026-78254High· 7.4
2w ago

The ftp and scp tasks of Apache Ant can download files from a remote server

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite…

▾ Twilightapache · antEPSS 0.52%via NVD
CVE-2026-78043Medium· 5.6
2w ago

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

▾ SunlitOpenVPN · OpenVPNEPSS 0.17%via NVD
CVE-2026-86258Medium· 5.9
3w ago

nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation

nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured …

▾ Sunlitjupyter · nbviewerEPSS 0.52%via NVD
CVE-2026-86253Medium· 5.9
3w ago

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic()

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decode…

▾ Sunlith3js · h3EPSS 0.62%via NVD
CVE-2026-86251Medium· 5.9PoC
3w ago

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives r…

▾ Twilighth3js · h3EPSS 0.43%via NVD
CVE-2026-67281High· 7.5PoC
3w ago

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare…

▾ Midnightmikrotik · routerosEPSS 0.73%via NVD
CVE-2026-84898Medium· 6.6
3w ago

The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.

The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.

▾ SunlitEPSS 0.43%via NVD
CVE-2026-14975Medium· 6.5
3w ago

The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter

The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access an…

▾ SunlitEPSS 0.68%via NVD
CVE-2025-15693Low· 2.7
3w ago

The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and…

The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-85690High· 7.8
3w ago

Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory

Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model output through poisoned repository files or attacker-contr…

▾ TwilightEPSS 0.20%via NVD
CVE-2026-85685High· 7.5
3w ago

AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter

AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any direct…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-85661Critical· 9.8
3w ago

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any …

▾ Midnightharis-musa · excel-mcp-serverEPSS 0.69%via NVD
CVE-2026-85606High· 7.5
3w ago

firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation

firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or di…

▾ Twilightfirecrawl · firecrawl-mcp-serverEPSS 0.90%via NVD
CVE-2026-85618Medium· 6.5
3w ago

ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives

ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\input{path}…

▾ SunlitC4illin · ConvertXEPSS 0.48%via NVD
CVE-2026-74236Medium· 6.5
3w ago

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly …

▾ SunlitEPSS 0.93%via NVD
CVE-2026-81939Critical· 9.1
3w ago

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted ar…

A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted ar…

▾ MidnightEPSS 0.68%via NVD
CVE-2026-85580Medium· 6.5
3w ago

SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems

SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-va…

▾ SunlitEPSS 0.58%via NVD
CWE-22 vulnerabilities (CVEs) — page 11 · VulnSea