VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-82193Medium· 5.5
3w ago

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations…

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-67397None
3w ago

Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

▾ SunlitEPSS 0.17%via NVD
CVE-2026-74235Medium· 4.9
3w ago

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their value…

▾ SunlitGFI Software · GFI Exinda AIEPSS 0.84%via NVD
CVE-2026-53757Medium· 6.9
3w ago

Emlog is an open source website building system

Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's…

▾ Sunlitemlog · emlogEPSS 0.47%via NVD
CVE-2026-17622Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

▾ Sunlitlangflow · langflowEPSS 0.49%via NVD
CVE-2026-17621Medium· 5.4
3w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system

IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the sys…

▾ Sunlitlangflow · langflowEPSS 0.29%via NVD
CVE-2026-19306High· 7.7
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and…

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and…

▾ Twilightlangflow · langflowEPSS 0.40%via NVD
CVE-2026-14470Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system

IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on th…

▾ Sunlitlangflow · langflowEPSS 0.34%via NVD
CVE-2026-9138Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent

IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using at…

▾ Sunlitlangflow · langflowEPSS 0.41%via NVD
CVE-2026-19303High· 8.1
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

▾ Twilightlangflow · langflowEPSS 0.40%via NVD
CVE-2026-19302Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

▾ Sunlitlangflow · langflowEPSS 0.49%via NVD
CVE-2026-19299Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.

▾ Sunlitlangflow · langflowEPSS 0.49%via NVD
CVE-2026-79707None
3w ago

A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query …

A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query …

▾ SunlitEPSS 0.67%via NVD
CVE-2026-85665Medium· 6.5
3w ago

Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments

Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a re…

▾ SunlitEPSS 0.77%via NVD
CVE-2026-50553High
3w ago

Note Mark is an open-source note-taking application

Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". huma compiles this with regexp.MustCompile(s.Pattern) and tests i…

▾ Twilightenchant97 · github.com/enchant97/note-mark/backendEPSS 0.46%via NVD
CVE-2026-85396High· 7.5
3w ago

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with nam…

▾ Twilightrubyzip · rubyzipEPSS 0.56%via NVD
CVE-2026-82521Medium· 5.3
3w ago

parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject

parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path traversal sequences, the filename sanitization function produces an empty …

▾ Sunlitdomainaware · parsedmarcEPSS 0.43%via NVD
CVE-2026-85124High· 7.5
3w ago

@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream

@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation tha…

▾ Twilightfastify · fastify/http-proxyEPSS 0.74%via NVD
CVE-2026-85456Medium· 5.5
3w ago

MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory

MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. Attackers can supply crafted alog files with backslash sequen…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-69086High· 7.7
3w ago

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclo…

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.53%via OSV
CVE-2026-75602Medium· 6.5
3w ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a pe…

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenListEPSS 0.69%via NVD
GHSA-gw25-m53r-qh88Medium· 6.5
3w ago

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-84702High· 7.5
3w ago

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthen…

▾ TwilightEPSS 0.44%via NVD
CVE-2026-18672High· 7.5
3w ago

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file …

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file …

▾ TwilightEPSS 0.36%via NVD
CVE-2026-78602Medium· 5.3
3w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over …

▾ Sunlitelastic · maps_serverEPSS 0.56%via NVD
CVE-2026-59832High· 7.7
3w ago

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.46%via OSV
GHSA-p498-v437-472gMedium
3w ago

humanfs: Recursive copy follows symlinked files and copies data from outside the source tree

humanfs: Recursive copy follows symlinked files and copies data from outside the source tree

▾ Sunlithumanfs · @humanfs/nodevia GHSA
CVE-2026-52832Medium· 4.9PoC
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP auth mode). The spec.handler field (e.g., mymodule:…

▾ Twilightnuclio · github.com/nuclio/nuclioEPSS 0.56%via NVD
CVE-2026-49831Medium· 5.5
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r param…

▾ Sunlitdspace · org.dspace:dspace-apiEPSS 0.53%via NVD
CVE-2026-49833Medium· 5.5
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerability is possible…

▾ Sunlitdspace · org.dspace:dspace-apiEPSS 0.37%via NVD
CWE-22 vulnerabilities (CVEs) — page 12 · VulnSea