VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-81730High· 8.2
1mo ago

Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php b…

▾ TwilightDolibarr · dolibarrEPSS 0.56%via CVEORG
CVE-2026-47884Critical· 9.8PoC
1mo ago

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spr…

▾ Abyssalvmware · spring_frameworkEPSS 0.60%via NVD
CVE-2026-76639High· 8.8PoC
1mo ago

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to…

▾ MidnightEPSS 0.67%via NVD
CVE-2026-81726High· 8.7
1mo ago

nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs (CVE-2026-81726)

A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on file…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.34%via CSAF
CVE-2026-40526Medium· 6.5
1mo ago

Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint

Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route par…

▾ SunlitEPSS 0.80%via NVD
CVE-2026-81560Medium· 5.3
1mo ago

A vulnerability was identified in blackms aistack up to 1.6.1

A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to pa…

▾ SunlitEPSS 0.69%via NVD
CVE-2026-54687Critical· 9.8
1mo ago

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n

n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workf…

▾ Midnightdangerblack · n8n-node-sqlite3EPSS 0.58%via NVD
CVE-2026-54732Medium· 6.5
1mo ago

libreoffice-convert is a Node.js module for converting office documents to different formats

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base n…

▾ Sunlitlibreoffice-convert · libreoffice-convertEPSS 0.42%via NVD
CVE-2026-81030Medium· 6.5
1mo ago

Mage AI does not confine the paths accepted by its browser-items API to the project directory

Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the filesystem read and write helpers wit…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-81028Medium· 4.9
1mo ago

ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries

ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absoluteP…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-73102Medium· 5.7
1mo ago

RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path

RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-57171High· 7.7
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author comma…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.22%via NVD
CVE-2026-75328High· 7.5
1mo ago

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

▾ TwilightEPSS 0.50%via NVD
CVE-2026-61792High· 7.7
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, w…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-54590Medium· 5.9
1mo ago

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

▾ Sunlitasyncssh · asyncsshEPSS 0.39%via OSV
CVE-2026-54591High· 8.1
1mo ago

asyncssh has SCP Path Traversal to Arbitrary File Write

asyncssh has SCP Path Traversal to Arbitrary File Write

▾ Twilightasyncssh · asyncsshEPSS 0.49%via OSV
CVE-2026-54550High· 7.4
1mo ago

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.j…

▾ Twilightcodehaus · org.codehaus.izpack:izpack-installerEPSS 0.45%via NVD
CVE-2026-63179Medium· 4.9
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) dire…

▾ Sunlitwinter · winter/wn-backend-moduleEPSS 0.52%via NVD
CVE-2026-57863High· 8.8
1mo ago

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives wit…

Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives wit…

▾ TwilightEPSS 0.90%via NVD
GHSA-896w-cw95-xq7wHigh· 8.1
1mo ago

Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-rj4c-4q9x-543xHigh· 6.5
1mo ago

Duplicate Advisory: Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Duplicate Advisory: Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-34968High· 8.1
1mo ago

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file pat…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-78679Medium· 6.5
1mo ago

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arb…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.26%via NVD
GHSA-7r39-6q8m-qw68High· 7.5
1mo ago

Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

▾ Twilightgitpython · gitpythonvia GHSA
CVE-2026-79674High· 7.5
1mo ago

nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)

A flaw was found in NLTK. A path traversal vulnerability in corpus-reader constructors allows a remote attacker to bypass the intended data root sandbox. By supplying arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.39%via CSAF
CVE-2026-80104Critical· 9.8
1mo ago

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-79781Medium· 6.5
1mo ago

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-sec…

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.34%via NVD
CVE-2026-55629High
1mo ago

Whistle vulnerable to path traversal

Whistle vulnerable to path traversal

▾ Twilightwhistle · whistleEPSS 0.67%via GHSA
GHSA-88g4-74f3-63x9Medium· 4.9
1mo ago

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

▾ Sunlitthorsten · thorsten/phpmyfaqvia GHSA
CVE-2026-55092High· 7.5
1mo ago

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

▾ Twilightaquasecurity · github.com/aquasecurity/trivyEPSS 0.44%via GHSA
CWE-22 vulnerabilities (CVEs) — page 14 · VulnSea