VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-53584Medium· 4.3
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal compon…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-69400Critical· 9.6
1mo ago

Azure Logic Apps Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Logic AppsEPSS 0.94%via CVEORG
CVE-2026-61625Medium· 6.8
1mo ago

VictoriaMetrics is a scalable solution for monitoring and managing time series data

VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/bac…

▾ SunlitVictoriaMetrics · github.com/VictoriaMetrics/VictoriaMetricsEPSS 0.40%via NVD
CVE-2026-63490High· 7.5
1mo ago

Handlebars.java provides logic-less and semantic Mustache templates with Java

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…

▾ Twilightgithub · com.github.jknack:handlebars-springmvcEPSS 0.69%via NVD
CVE-2026-71492Medium· 6.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…

▾ Sunlitbanks · banksEPSS 0.47%via NVD
GHSA-2223-f22x-24cqMedium· 4.9
1mo ago

Winter: Local File Inclusion through =include directives in JavaScript asset compilation

Winter: Local File Inclusion through =include directives in JavaScript asset compilation

▾ Sunlitwinter · winter/wn-system-modulevia GHSA
CVE-2026-49244Medium· 5.9
1mo ago

SFTPGo is an open source, event-driven file transfer solution

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison ra…

▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.45%via NVD
CVE-2026-76832High· 8.8
1mo ago

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument pas…

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument pas…

▾ TwilightEPSS 1.3%via NVD
CVE-2026-53452Medium· 5.3
1mo ago

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-p…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-53451Critical· 9.8
1mo ago

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled sn…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-75593High· 7.2
1mo ago

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from …

▾ Twilightmoby · buildkitEPSS 0.72%via NVD
CVE-2026-48024Critical· 9.1
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlle…

▾ Midnightwazuh · wazuhEPSS 0.78%via NVD
CVE-2026-76614Medium· 4.3
1mo ago

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function

OpenEMR before 8.3.0 contains a path traversal vulnerability in the EDI archive restore function. The archrestore_sel POST parameter is passed to the archive restore handler without sanitization for path traversal sequences. The handler …

▾ SunlitEPSS 0.40%via NVD
CVE-2026-46343High· 7.2
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authentica…

▾ Twilightwazuh · wazuhEPSS 0.42%via NVD
CVE-2026-44829High· 8.8
1mo ago

Gotenberg is a Docker-powered stateless API for PDF files

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename c…

▾ TwilightEPSS 0.50%via NVD
GHSA-3vrx-526r-64rmHigh· 8.2
1mo ago

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

▾ Twilightgitpython · gitpythonvia GHSA
CVE-2026-62680High· 7.1
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. P…

▾ Twilightorval · orvalEPSS 0.40%via NVD
CVE-2026-76222High· 8.2
1mo ago

gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
CVE-2026-63188High
1mo ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static as…

▾ Twilightlogto · @logto/tunnelEPSS 0.54%via NVD
GHSA-cc2g-gq8c-r332High· 7.5
1mo ago

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

▾ Twilightgrok-faf-mcp · grok-faf-mcpvia GHSA
GHSA-j4r7-8ph4-43g3High· 7.5
1mo ago

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightfaf-mcp · faf-mcpvia GHSA
GHSA-rr55-jp92-8wp2High· 7.5
1mo ago

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightclaude-faf-mcp · claude-faf-mcpvia GHSA
CVE-2026-53951High
1mo ago

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2026-49253High· 7.1
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/z…

▾ Twilightelecterm · electermEPSS 0.44%via NVD
CVE-2026-45532None
1mo ago

DataEase is an open source data visualization and analysis tool

DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` charact…

▾ SunlitEPSS 0.52%via NVD
GHSA-2rhw-8953-48q3High· 5.9
1mo ago

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-73973Medium· 5.5
1mo ago

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-52875None
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the res…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-52872High· 8.8
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-50186High· 8.8
1mo ago

4gaBoards is a boards system for realtime project management

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controll…

▾ TwilightEPSS 0.59%via NVD
CWE-22 vulnerabilities (CVEs) — page 16 · VulnSea