VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-47699Medium· 6.4
1mo ago

Confidential Containers Guest Components provides guest tools and components for confidential container workloads

Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafted OCI image layer can make image_rs::stream::unpack::unpack() create a hardlink outside …

▾ SunlitEPSS 0.37%via NVD
CVE-2026-53457None
1mo ago

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd …

▾ SunlitEPSS 0.76%via NVD
CVE-2026-74044Medium· 6.5
1mo ago

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. A…

▾ Sunlitwazuh · wazuhEPSS 0.60%via NVD
CVE-2026-74038High· 7.1PoC
1mo ago

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers …

▾ Midnightwazuh · wazuhEPSS 0.55%via NVD
CVE-2026-75855High· 8.7PoC
1mo ago

ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configure…

ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing authenticated root users to write and delete arbitrary files outside the configure…

▾ MidnightEPSS 0.55%via NVD
CVE-2026-75842High· 7.7
1mo ago

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-74907Medium· 5.9
1mo ago

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling direc…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.43%via NVD
CVE-2026-75914High· 7.5
1mo ago

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image ext…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.53%via NVD
CVE-2026-75859High· 7.5
1mo ago

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can …

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.53%via NVD
CVE-2026-55224HighPoC
1mo ago

MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall

▾ Midnightmineadmin · mineadmin/mineadminvia GHSA
CVE-2026-17106High· 7.8PoC
1mo ago

github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction (CVE-2026-17106)

A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by…

▾ MidnightRed Hat · Red Hat Edge Manager 1.2EPSS 0.44%via CSAF
CVE-2026-73974Medium· 5.5
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linux…

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.17%via NVD
CVE-2026-68922Medium· 5.5
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource d…

▾ Sunlitmobsf · mobsfEPSS 0.46%via NVD
GHSA-2mf3-mr2r-r4vfHigh· 7.5
1mo ago

@rhinostone/swig: arbitrary local file read via include/extends path traversal

@rhinostone/swig: arbitrary local file read via include/extends path traversal

▾ Twilightrhinostone · @rhinostone/swigvia GHSA
CVE-2026-63328Medium
1mo ago

Trivy is a security scanner

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to that root, allowing an attacker who persuades a user to i…

▾ Sunlitaquasecurity · github.com/aquasecurity/trivyEPSS 0.19%via NVD
CVE-2026-48798High· 7.1
1mo ago

SSH.NET is a Secure Shell (SSH) library for .NET

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the r…

▾ TwilightSSH · SSH.NETEPSS 0.42%via NVD
CVE-2026-48796Medium· 5.3
1mo ago

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsW…

▾ SunlitCefSharp · CefSharp.CommonEPSS 0.40%via NVD
CVE-2026-75104Medium· 5.5PoC
1mo ago

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or…

▾ Twilighthuggingface · transformersEPSS 0.29%via NVD
CVE-2026-75111High· 7.5
1mo ago

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences …

▾ Twilightevidentlyai · evidentlyEPSS 0.57%via NVD
CVE-2026-75482High· 7.5PoC
1mo ago

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassin…

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassin…

▾ MidnightSWE-agent · SWE-agentEPSS 0.76%via NVD
CVE-2026-73646High· 7.5
1mo ago

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to joi…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.53%via NVD
CVE-2026-73851None
1mo ago

Kiota is an OpenAPI based HTTP Client code generator

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (…

▾ SunlitEPSS 2.3%via NVD
CVE-2026-54336Medium· 5.4
1mo ago

JumpServer is an open source bastion host and an operation and maintenance security audit system

JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user with SFTP permission to an authorized asset can submit crafted traversal paths through the …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-40506Medium· 6.5
1mo ago

OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins the value to the PHP temporary directory …

OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins the value to the PHP temporary directory …

▾ SunlitEPSS 0.70%via NVD
CVE-2026-57233High· 8.1
1mo ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTo…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-52886NonePoC
1mo ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup directory without path normalization, al…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-67918High· 7.5
1mo ago

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint

▾ TwilightEPSS 1.4%via NVD
CVE-2026-50776High· 7.5
1mo ago

Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.

Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.

▾ TwilightEPSS 1.8%via NVD
CVE-2026-19693High· 8.1
1mo ago

extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)

A flaw was found in extract-zip. This vulnerability allows a remote attacker to perform an arbitrary file write outside the intended destination directory. By crafting a malicious zip archive containing a symbolic link (symlink) and a regu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.28%via CSAF
CVE-2026-63667Medium· 6.5
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and ex…

▾ Sunlitapostrophecms · @apostrophecms/import-exportEPSS 0.46%via NVD
CWE-22 vulnerabilities (CVEs) — page 17 · VulnSea