VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-53766Medium· 6.1
1mo ago

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.12%via GHSA
CVE-2026-69148High· 7.1
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in…

▾ Twilightmlflow · mlflowEPSS 0.37%via NVD
GHSA-92hr-gmr6-h8cpMedium
1mo ago

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

▾ Sunlitep_etherpad-lite · ep_etherpad-litevia GHSA
CVE-2026-46345High· 8.4
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does …

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.20%via NVD
CVE-2026-15056Medium· 6.5
1mo ago

The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function

The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.1 via the parse_file_path function. This mak…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-14524Critical· 9.1
1mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-74764None
1mo ago

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applyi…

▾ SunlitEPSS 0.61%via NVD
CVE-2026-18855Critical· 9.1
1mo ago

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthen…

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthen…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-72820Medium· 4.9
1mo ago

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup …

▾ SunlitEPSS 0.50%via NVD
CVE-2026-72814Medium· 5.3
1mo ago

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the serv…

▾ SunlitRed Hat · Red Hat OpenShift Update ServiceEPSS 0.47%via NVD
CVE-2026-55156Medium· 5.3
1mo ago

Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

▾ Sunlitooples · @ooples/token-optimizer-mcpvia GHSA
CVE-2026-73653Critical· 9.4
1mo ago

Vitest is a testing framework powered by Vite

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accep…

▾ MidnightEPSS 0.79%via NVD
CVE-2026-73659High· 8.1
1mo ago

Trigger.dev is the open-source platform for building AI workflows in TypeScript

Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtoc…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-73658High· 8.2
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign us…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-73657Medium· 4.2
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-70460High· 8.1
1mo ago

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.54%via NVD
CVE-2026-67613Medium· 4.9
1mo ago

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attacker…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-73509High· 7.6
1mo ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and valid…

▾ TwilightOpenListTeam · github.com/OpenListTeam/OpenList/v4EPSS 0.52%via NVD
GHSA-rm43-82j9-r4mjHigh
1mo ago

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read

▾ Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
CVE-2026-45774Medium
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them wi…

▾ Sunlitcompliance-trestle · compliance-trestleEPSS 0.54%via NVD
CVE-2026-48099High· 7.1
1mo ago

WsgiDAV is a generic and extendable WebDAV server based on WSGI

WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path lay…

▾ Twilightwsgidav · wsgidavEPSS 0.41%via NVD
CVE-2026-73291High· 7.1
1mo ago

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache fi…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-16033High· 8.5
1mo ago

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from es…

▾ Twilightcanonical · lxdEPSS 0.35%via NVD
CVE-2026-66898Critical· 9.9
1mo ago

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names c…

▾ Midnightcanonical · lxdEPSS 0.59%via NVD
CVE-2026-64826Medium· 6.5
1mo ago

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() metho…

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() metho…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-73407None
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination t…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-19594High· 8.1
1mo ago

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path s…

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path s…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-65939Medium· 6.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

▾ SunlitEPSS 0.38%via NVD
CVE-2026-66382Medium· 4.3
1mo ago

An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

▾ SunlitEPSS 0.35%via NVD
CVE-2026-66381Medium· 5.3
1mo ago

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

▾ SunlitEPSS 0.39%via NVD
CWE-22 vulnerabilities (CVEs) — page 18 · VulnSea