VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-73752High· 8.8
3w ago

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to …

▾ Twilighthpe · arubaos-cxEPSS 0.47%via NVD
CVE-2026-67395Medium· 5.9
3w ago

A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters

A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may b…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-84365Medium· 6.5
3w ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the c…

▾ Sunlithono · honoEPSS 0.44%via NVD
CVE-2026-84374High· 7.5
3w ago

Laravel Excel provides supercharged Excel exports and imports in Laravel

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::…

▾ Twilightmaatwebsite · maatwebsite/excelEPSS 0.84%via NVD
CVE-2026-84373Medium· 5.9
3w ago

Vitest is a testing framework powered by Vite

Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:regi…

▾ Sunlitvitest · @vitest/mockerEPSS 0.53%via NVD
CVE-2026-75604Critical· 9.0PoC
3w ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently esc…

▾ Abyssalnext · nextEPSS 2.3%via NVD
CVE-2026-84201High· 7.1
3w ago

appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory

appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths …

▾ TwilightEPSS 0.19%via NVD
GHSA-2rx9-3g3h-c2jvHigh· 7.1
3w ago

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

▾ Twilightpnpm · pnpmvia GHSA
CVE-2026-82877Medium· 6.5
3w ago

ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports

ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can cons…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-61639None
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with …

▾ SunlitEPSS 0.51%via NVD
CVE-2026-79743None
3w ago

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, MCPB File Upload Handler extracts a ZIP file and r…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-79407High· 7.5
3w ago

A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py

A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code jo…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-75592Medium
3w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Ki…

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.68%via NVD
CVE-2026-82393High· 7.5
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

▾ Twilightpnpm · pnpmEPSS 0.63%via NVD
CVE-2026-82392High· 7.1
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…

▾ Twilightpnpm · pnpmEPSS 0.61%via NVD
CVE-2026-75594High
3w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated pare…

▾ Twilightgetkirby · getkirby/cmsEPSS 0.76%via NVD
CVE-2026-53553High· 7.7
3w ago

Goploy is an open-source automation deployment system

Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by…

▾ Twilightzhenorzz · github.com/zhenorzz/goployEPSS 0.46%via NVD
CVE-2026-56718High· 7.5PoC
4w ago

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path trav…

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path trav…

▾ MidnightEPSS 0.94%via NVD
CVE-2026-82656Low· 2.6
4w ago

Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names

Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names. Attackers can craft malicious…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-82635High· 8.8
4w ago

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/c…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-82460Critical· 9.8
4w ago

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move…

▾ MidnightEPSS 0.90%via NVD
CVE-2026-82286High· 8.6PoC
1mo ago

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. Attackers can supply absolute paths or parent-direc…

▾ MidnightBuilderIO · gpt-crawlerEPSS 0.52%via NVD
CVE-2026-82275High· 7.5PoC
1mo ago

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories

Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read…

▾ MidnightQwenLM · qwen-agentEPSS 0.46%via NVD
CVE-2026-82264Medium· 6.8
1mo ago

Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files

Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft malicious snapshot entries with directory traversal sequence…

▾ Sunlitgilbertchen · duplicacyEPSS 0.71%via NVD
CVE-2026-75337Critical· 9.8
1mo ago

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attack…

▾ MidnightEPSS 0.60%via NVD
CVE-2026-38093Low· 3.3
1mo ago

file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation

file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses the DISPLAY_NAME obtained from Cont…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-61800Critical· 9.1
1mo ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files unde…

▾ Midnightwazuh · wazuhEPSS 0.98%via NVD
CVE-2026-54083High· 8.1
1mo ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or de…

▾ Twilightwazuh · wazuhEPSS 0.57%via NVD
CVE-2026-55569Medium· 6.6
1mo ago

aqua is a declarative command-line version manager written in Go

aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains un…

▾ Sunlitaquaproj · github.com/aquaproj/aqua/v2EPSS 0.18%via NVD
CVE-2026-55552High· 7.5
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.55%via NVD
CWE-22 vulnerabilities (CVEs) — page 13 · VulnSea