VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2026-64677None
1mo ago

Anki is a program for creating and reviewing flashcards

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious…

▾ SunlitEPSS 1.0%via NVD
GHSA-7hxc-f267-h5q7Low
1mo ago

Craft CMS: Incorrect path validation could potentially lead to path traversal

Craft CMS: Incorrect path validation could potentially lead to path traversal

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-71476High
1mo ago

Nx is a monorepo solution for TypeScript and polyglot codebases

Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malici…

▾ Twilightnx · nxEPSS 0.86%via NVD
CVE-2026-65600Critical· 9.1
1mo ago

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

▾ Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.62%via GHSA
CVE-2026-70428Medium· 4.3
1mo ago

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations…

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations…

▾ Sunlitjenkins · jenkinsEPSS 0.43%via NVD
CVE-2026-9195Critical· 9.3
1mo ago

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the adm…

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the adm…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-71215High· 7.5
1mo ago

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that …

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that …

▾ TwilightEPSS 0.56%via NVD
CVE-2026-71209High· 7.5PoC
1mo ago

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F…

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F…

▾ MidnightEPSS 1.9%via NVD
CVE-2026-55747Medium· 6.8
1mo ago

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and…

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-71309High
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../ in cmd/serve/restic/restic…

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.46%via NVD
GHSA-8v25-v8p6-qf7vMedium· 6.5
1mo ago

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

rclone: Path traversal in serve s3 allows reading and overwriting root-level files

▾ Sunlitrclone · github.com/rclone/rclonevia GHSA
CVE-2026-59733High· 8.8
1mo ago

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.55%via GHSA
CVE-2026-59732Medium· 5.0
1mo ago

rclone archive extract allows S3 destination prefix escape via crafted archive paths

rclone archive extract allows S3 destination prefix escape via crafted archive paths

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.20%via OSV
CVE-2026-71313Medium· 6.9
1mo ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent …

▾ Sunlitrclone · github.com/rclone/rcloneEPSS 0.37%via NVD
CVE-2026-69110Critical· 9.1
1mo ago

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFil…

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFil…

▾ MidnightEPSS 0.84%via NVD
CVE-2026-47682None
1mo ago

CVAT is an open source interactive video and image annotation tool for computer vision

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-67200High· 7.5
1mo ago

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments in HTTP request URL paths. Attackers can bypass t…

▾ TwilightEPSS 0.85%via NVD
CVE-2026-56845High· 7.5
1mo ago

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the ba…

▾ TwilightEPSS 0.60%via NVD
CVE-2026-47612High· 7.5
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information…

▾ Twilightnvidia · dynamoEPSS 0.82%via NVD
CVE-2026-70593Medium· 6.6
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation t…

▾ Sunlitghost · ghostEPSS 0.41%via NVD
CVE-2026-70592Medium· 5.5
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issu…

▾ Sunlitghost · ghostEPSS 0.44%via NVD
GHSA-88pr-878c-24wfHigh
1mo ago

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

▾ Twilightflowise-components · flowise-componentsvia GHSA
CVE-2026-47764High
1mo ago

pdm is a Python package and dependency manager supporting the latest PEP standards

pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overr…

▾ Twilightpdm · pdmEPSS 0.20%via NVD
GHSA-mmwh-j75q-gxp8High· 7.5
1mo ago

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-69095High· 7.5
1mo ago

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attac…

▾ TwilightEPSS 0.93%via NVD
GHSA-3f7w-8rr8-f37fHigh· 8.1
1mo ago

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-69153High· 7.5
1mo ago

postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153)

A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and exp…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.45%via CSAF
CVE-2026-9856High· 7.1
1mo ago

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMix…

▾ Twilighttransformers · transformersEPSS 0.46%via NVD
CVE-2026-9335Medium· 6.5PoC
1mo ago

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_g…

▾ TwilightEPSS 0.77%via NVD
CVE-2026-18352High· 7.5
1mo ago

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the con…

▾ TwilightEPSS 1.0%via NVD
CWE-22 vulnerabilities (CVEs) — page 21 · VulnSea