VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

892 CVEsRSS

CVE-2026-54520High· 8.1PoC
4d ago

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.…

MidnightvmDeshpande · ai-agent-automationEPSS 0.40%via NVD
CVE-2026-54343High· 8.7
4d ago

Frappe Learning Management System (LMS) is a learning system that helps users structure their content

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The …

Twilightfrappe · lmsEPSS 0.48%via NVD
CVE-2026-53554High· 7.3PoC
4d ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename …

Midnightdataease · SQLBotEPSS 0.36%via NVD
CVE-2026-72697High· 6.5
4d ago

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Twilightgetgrav · getgrav/gravEPSS 0.31%via GHSA
CVE-2026-72695High· 8.1
4d ago

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Twilightgetgrav · getgrav/gravEPSS 0.57%via GHSA
CVE-2026-15815High· 8.8
4d ago

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary fi…

TwilightGrafana · Grafana OSSEPSS 0.87%via NVD
CVE-2026-45140Critical· 9.8PoC
4d ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

Abyssalchamilo · chamilo-lmsEPSS 0.98%via NVD
CVE-2026-45723Low· 2.7
4d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClie…

Sunlitsiderolabs · omniEPSS 0.39%via NVD
CVE-2026-89038Medium· 6.2PoC
4d ago

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

TwilightVerizon · com.vcast.mediamanagerEPSS 0.15%via NVD
CVE-2026-54053Critical· 9.6
4d ago

Many Notes is a Markdown note-taking web application designed for simplicity

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segme…

Midnightbrufdev · many-notesEPSS 0.70%via NVD
CVE-2026-69089High
4d ago

Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Twilightgetgrav · getgrav/gravEPSS 0.37%via GHSA
CVE-2026-54585Medium· 6.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malici…

SunlitMidnightBSD · mportEPSS 0.52%via NVD
CVE-2026-54583High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index d…

TwilightMidnightBSD · mportEPSS 0.52%via NVD
CVE-2026-93014High· 7.1PoC
4d ago

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal

RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path traversal. Attackers can use parent-directory sequences to …

MidnightRosarioSIS · RosarioSISEPSS 0.39%via NVD
CVE-2026-93013Medium· 4.3
4d ago

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in…

RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in…

Sunlitinfiniflow · ragflowEPSS 0.35%via NVD
CVE-2026-86864High· 8.8
4d ago

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation

pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options…

Twilightpgadmin · pgadmin_4EPSS 0.38%via NVD
CVE-2026-92970High· 8.8
4d ago

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository

HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequence…

Twilighthubzero · hubzero-cmsEPSS 0.52%via NVD
CVE-2026-92945Medium· 4.2
4d ago

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison

vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted packages sharing a prefix with…

Sunlitpatriksimek · vm2EPSS 0.21%via NVD
CVE-2026-81829Medium· 5.3
4d ago

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch UR…

SunlitRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.39%via NVD
CVE-2026-81453Medium· 6.5
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially ex…

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.44%via NVD
CVE-2026-92919High· 8.1PoC
4d ago

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to …

Midnightcjbi · admin3EPSS 0.38%via NVD
CVE-2026-81481High· 7.5
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially …

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.53%via NVD
CVE-2026-55062High· 8.4
4d ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

Twilightuniget-org · cliEPSS 0.13%via NVD
CVE-2026-54617Critical· 9.8
4d ago

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274…

MidnightGravitLauncher · LauncherEPSS 0.68%via NVD
CVE-2026-92748High· 8.8PoC
5d ago

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in th…

MidnightBC-SECURITY · EmpireEPSS 0.66%via NVD
CVE-2026-92791High· 7.5PoC
5d ago

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments i…

Midnightuber · krakenEPSS 0.51%via NVD
CVE-2026-92812Medium· 6.8PoC
5d ago

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access sibling directories whose names begin with the rep…

Twilightdecaporg · decap-serverEPSS 0.29%via NVD
CVE-2026-92816High· 7.8PoC
5d ago

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory

ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arbitrary paths outside the output directory. Attackers can load a crafted workflow that writes attacker-controlled con…

MidnightComfy-Org · ComfyUIEPSS 0.16%via NVD
CVE-2026-87976High· 8.1
5d ago

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coord…

Twilightapache · nifiEPSS 0.39%via NVD
CVE-2026-89084High· 8.8
5d ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

TwilightHP Inc · HP AC Print & ScanEPSS 0.58%via NVD
CWE-22 vulnerabilities (CVEs) — page 2 · VulnSea