VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-13622High· 8.8
1mo ago

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symli…

▾ TwilightRed Hat · container-native-virtualization/virt-handlerEPSS 0.20%via NVD
CVE-2026-73327High· 7.6
1mo ago

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filen…

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filen…

▾ TwilightEPSS 0.85%via NVD
CVE-2026-73498High· 7.7
1mo ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassia…

▾ Twilightmcp-atlassian · mcp-atlassianEPSS 0.48%via NVD
CVE-2026-54917HighPoC
1mo ago

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

▾ Midnightseaweedfs · github.com/seaweedfs/seaweedfsEPSS 1.6%via OSV
CVE-2026-72713High· 7.5
1mo ago

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form fiel…

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form fiel…

▾ TwilightEPSS 0.83%via NVD
CVE-2026-73034Critical· 9.8PoC
1mo ago

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Pyt…

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Pyt…

▾ AbyssalEPSS 5.7%via NVD
CVE-2026-73079High· 8.5
1mo ago

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider…

▾ TwilightWei-Shaw · sub2apiEPSS 0.39%via NVD
CVE-2026-63134Medium· 5.4
1mo ago

Malcolm is a network traffic analysis tool suite

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathnam…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-73244Medium· 5.3
1mo ago

kkFileView is a universal file online preview project based on Spring Boot

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the user-controlled path…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-73234High· 7.8
1mo ago

FreeCAD is a free and open-source multiplatform 3D parametric modeler

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the docu…

▾ TwilightEPSS 0.20%via NVD
CVE-2026-73227High· 8.1
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server to write attacker-controlled content outside the selected save directory because the RDP …

▾ TwilightEPSS 0.49%via NVD
CVE-2026-73225High· 8.1
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory beca…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-73223High· 8.1
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside the temporary directory because the server-…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-66777Medium· 5.9
1mo ago

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted request…

▾ Sunlitsap · approuterEPSS 0.44%via NVD
CVE-2026-65768High· 8.8
1mo ago

Microsoft Teams Remote Code Execution Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Teams for AndroidEPSS 0.94%via CVEORG
CVE-2026-71475Medium· 6.8
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly…

▾ Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.69%via NVD
CVE-2026-18640High· 7.1
1mo ago

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory

The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension o…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-33922Medium· 6.0
1mo ago

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-73030High· 8.1
1mo ago

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. …

▾ TwilightEPSS 0.59%via NVD
CVE-2026-70622Medium· 6.5
1mo ago

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…

▾ SunlitRed Hat · Red Hat OpenShift Update ServiceEPSS 0.46%via NVD
CVE-2026-73033Medium· 6.5PoC
1mo ago

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplyi…

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplyi…

▾ TwilightSucuri · sucuri-wordpress-pluginEPSS 0.93%via NVD
CVE-2026-72903High· 8.1
1mo ago

Tabby (formerly Terminus) is a highly configurable terminal emulator

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _ma…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4EPSS 0.49%via NVD
CVE-2026-47754Critical· 9.3
1mo ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-69112High· 7.1
1mo ago

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can…

▾ Twilightaccelerate · accelerateEPSS 0.19%via NVD
CVE-2026-72569Critical· 9.1
1mo ago

A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.

A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.

▾ MidnightEPSS 0.74%via NVD
CVE-2026-72567Critical· 9.8
1mo ago

An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges

An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or delete arbitrary files with root privileges. The api/api.py wiki-cache endpoint construc…

▾ MidnightEPSS 0.79%via NVD
CVE-2026-19372Medium· 5.3
1mo ago

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19371Medium· 5.3
1mo ago

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19370Medium· 5.3
1mo ago

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionComm…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-19368Low· 3.3
1mo ago

A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0

A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The mani…

▾ SunlitEPSS 0.17%via NVD
CWE-22 vulnerabilities (CVEs) — page 19 · VulnSea